Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. ManageEngine

ManageEngine

enriched
Data Loss PreventionIdentity & Access ManagementNetwork Detection & Response (NDR)

manageengine.com ↗ · required email domain for this vendor's users

Do you work at ManageEngine?

This profile was built from public sources and hasn't been claimed yet. Claiming it lets you correct what's wrong and add details only you can confirm — and marks that information as vendor-verified for buyers.

Free, and it does not affect ranking, placement, or comparison results. The first person verified on ManageEngine's email domain becomes the profile admin.

Claim this profileAlready have an account?

Trust profileHow to read thisFive separate questions a buyer actually asks, each answered with its own evidence and a link to the source. There is deliberately no overall score: a single number invites comparison it cannot support, and would mostly reflect how much of ManageEngine we have managed to scan rather than anything about the vendor.

Not checked means we have not looked yet, and is never counted against a vendor. Limited means we did look, but found only one line of evidence — enough to report, not enough to corroborate.

checked 6 of 16 signals
  • Limited

    Independently verified

    Has anyone other than the vendor confirmed this?

    checked 3 of 4

    Nothing here has been confirmed by an independent third party yet.

    • No third-party certifications found
    • Profile not claimed by the vendor
  • Limited

    Operating durability

    Is this a real, durable business?

    checked 2 of 4

    How long this vendor has been operating, and who stands behind them.

    • Headquarters location not disclosed on their site
  • Mixed

    Behaviour under stress

    What do they do when something goes wrong?

    checked 1 of 3

    What their public record shows about handling vulnerabilities and outages.

    • 100 published CVE(s) — a public disclosure record exists
    • 7 rated critical
  • Not checked

    Disclosure posture

    Do they tell you the awkward things unprompted?

    checked 0 of 3

    We have not checked what this vendor discloses publicly yet.

    Nothing checked here yet — this is not a mark against ManageEngine.

  • Not checked

    Momentum

    Are they still shipping, or coasting?

    checked 0 of 2

    We have not tracked this vendor's release activity yet.

    Nothing checked here yet — this is not a mark against ManageEngine.

Data coverage: 13/100What this measures (and doesn't)

Not a quality rating or endorsement — a measure of how much verified, disclosed data we actually have about this vendor. A low score usually means "we don't have much verified information yet," not "this is a bad vendor." Never used to sort or rank vendor lists.

Verification depth0/100
Security signal0/100
Buyer feedbackno data yet (0 reviews so far)
Profile completeness13/100
claim · HQ · materials · screenshots · integrations · certifications · security check

The platform admin controls the formula's weights.

Data coverage profileHow to read thisThe same four components behind the data coverage score above, shaped instead of listed — a vendor strong on verification but thin on buyer feedback looks visibly different from one that's the other way around. Security and feedback plot at the neutral midpoint (50) when there's no data yet (no products tracked, no reviews), matching how the actual score itself treats missing data — not a guess either way.

VerificationSecurityFeedbackCompletenessThis vendor — Verification: 0This vendor — Security: 0This vendor — Feedback: no data yetThis vendor — Completeness: 13

IntegrationsUI-12 — integration graphDetected from this vendor's own published integration/partner pages by the enrichment loop — each entry links the exact page it was found on. Directional: "integrates with" is claimed by this vendor; "integrated by" is claimed by the other vendor's site. Coverage grows as the scan progresses.

13 detected

Integrated by: Brandefense, CrowdStrike, Faradaysec, Lansweeper, Nagomi Security, OctoXLabs, ScalePad, Seceon Inc, Seemplicity, Simbian, Traceless, ZeroFox, torii

Buyer reviewsUI-14 — verified-buyer reviewsWritten only by domain-verified buyers at other companies, attributed to their company domain (never their identity), and moderated. Buyer-sourced opinion, clearly separate from the neutral catalog facts above — and never an input to search or comparison ordering.

verified buyers only

No buyer reviews yet.

Reputation ratingUI-20 — anonymous ratingA single anonymous 5-star signal from buyers, resellers, and analysts who've engaged with this vendor — separate from the domain-attributed reviews above. No rater identity is ever shown, not even at company level.

anonymous

No ratings in this window yet.

Integrated IAM suite for Active Directory and hybrid identity management AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →

CVE severity over timeUI-24 — CVE severity timelineEvery known CVE with a disclosure date and severity, plotted by when it was published — lets you see whether disclosures are trending toward more or less severe, not just a raw count. Same NVD-sourced, name-matched data as the list below.

LOWMEDIUMHIGHCRITICAL200620072008200920102011201220132014201520162017CVE-2017-16847 · CRITICAL 9.8 · 2017-11-16CVE-2017-16846 · CRITICAL 9.8 · 2017-11-16CVE-2017-11512 · HIGH 7.5 · 2017-11-09CVE-2017-11511 · HIGH 7.5 · 2017-11-09CVE-2017-16543 · CRITICAL 9.8 · 2017-11-05CVE-2017-16542 · HIGH 8.8 · 2017-11-05CVE-2015-8249 · CRITICAL 9.8 · 2017-09-28CVE-2017-14123 · HIGH 8.8 · 2017-09-05CVE-2015-9107 · CRITICAL 9.8 · 2017-08-04CVE-2017-11687 · MEDIUM 6.1 · 2017-07-27CVE-2017-11686 · MEDIUM 6.1 · 2017-07-27CVE-2017-11685 · MEDIUM 6.1 · 2017-07-27CVE-2017-11346 · CRITICAL 9.8 · 2017-07-17CVE-2015-7781 · HIGH 7.5 · 2017-06-28CVE-2015-7780 · MEDIUM 6.5 · 2017-06-28CVE-2017-7213 · CRITICAL 10.0 · 2017-05-15CVE-2016-1161 · HIGH 8.0 · 2017-04-21CVE-2016-4890 · MEDIUM 5.3 · 2017-04-14CVE-2016-4889 · HIGH 8.8 · 2017-04-14CVE-2016-4888 · MEDIUM 5.4 · 2017-04-14CVE-2015-7766 · HIGH 9.0 · 2015-10-09CVE-2015-7765 · HIGH 9.0 · 2015-10-09CVE-2015-7387 · HIGH 7.5 · 2015-09-28CVE-2015-5459 · MEDIUM 6.5 · 2015-07-08CVE-2015-5150 · LOW 3.5 · 2015-06-30CVE-2015-5149 · MEDIUM 5.5 · 2015-06-30CVE-2015-5061 · LOW 3.5 · 2015-06-24CVE-2015-2169 · MEDIUM 4.3 · 2015-06-24CVE-2015-1026 · MEDIUM 4.3 · 2015-03-11CVE-2015-1480 · MEDIUM 4.0 · 2015-02-04CVE-2015-1479 · MEDIUM 6.5 · 2015-02-04CVE-2014-9331 · MEDIUM 6.8 · 2015-02-04CVE-2014-7864 · HIGH 7.5 · 2015-02-04CVE-2015-0866 · MEDIUM 4.3 · 2015-02-02CVE-2014-100002 · MEDIUM 5.0 · 2015-01-13CVE-2014-3779 · MEDIUM 4.3 · 2015-01-07CVE-2014-9373 · HIGH 10.0 · 2014-12-16CVE-2014-9372 · MEDIUM 6.4 · 2014-12-16CVE-2014-9371 · HIGH 10.0 · 2014-12-16CVE-2014-7866 · HIGH 7.5 · 2014-12-10CVE-2014-3997 · HIGH 7.5 · 2014-12-05CVE-2014-3996 · HIGH 7.5 · 2014-12-05CVE-2014-7868 · HIGH 7.5 · 2014-12-04CVE-2014-7867 · HIGH 7.5 · 2014-12-04CVE-2014-6036 · MEDIUM 6.4 · 2014-12-04CVE-2014-6035 · HIGH 7.5 · 2014-12-04CVE-2014-6034 · MEDIUM 5.0 · 2014-12-04CVE-2014-5446 · MEDIUM 5.0 · 2014-12-04CVE-2014-5445 · MEDIUM 5.0 · 2014-12-04CVE-2014-8678 · HIGH 7.8 · 2014-11-25CVE-2014-8499 · MEDIUM 6.5 · 2014-11-17CVE-2014-8498 · MEDIUM 6.5 · 2014-11-17CVE-2014-6037 · HIGH 7.5 · 2014-10-26CVE-2014-5006 · HIGH 7.5 · 2014-10-21CVE-2014-5005 · HIGH 7.5 · 2014-10-21CVE-2014-6043 · MEDIUM 6.5 · 2014-09-11CVE-2014-5377 · MEDIUM 5.0 · 2014-09-04CVE-2014-4930 · MEDIUM 4.3 · 2014-08-29CVE-2014-5103 · MEDIUM 4.3 · 2014-07-25CVE-2014-2670 · LOW 3.5 · 2014-03-30CVE-2014-0344 · MEDIUM 6.5 · 2014-03-30CVE-2012-5956 · MEDIUM 4.3 · 2012-12-11CVE-2012-4891 · MEDIUM 4.3 · 2012-09-11CVE-2012-4889 · MEDIUM 4.3 · 2012-09-11CVE-2011-5105 · MEDIUM 4.3 · 2012-08-24CVE-2012-2585 · MEDIUM 4.3 · 2012-08-13CVE-2012-1063 · HIGH 7.5 · 2012-02-14CVE-2012-1062 · MEDIUM 4.3 · 2012-02-14CVE-2012-1049 · MEDIUM 4.3 · 2012-02-14CVE-2010-5050 · MEDIUM 4.3 · 2011-11-23CVE-2010-4841 · MEDIUM 4.3 · 2011-09-27CVE-2010-4840 · HIGH 7.5 · 2011-09-27CVE-2011-1510 · MEDIUM 4.3 · 2011-09-20CVE-2011-1509 · MEDIUM 5.0 · 2011-09-20CVE-2011-2757 · MEDIUM 5.0 · 2011-07-18CVE-2011-2756 · MEDIUM 5.0 · 2011-07-18CVE-2011-2755 · MEDIUM 5.0 · 2011-07-18CVE-2010-3274 · MEDIUM 4.3 · 2011-02-17CVE-2010-3273 · MEDIUM 5.0 · 2011-02-17CVE-2010-3272 · MEDIUM 4.3 · 2011-02-17CVE-2010-2049 · MEDIUM 4.3 · 2010-05-25CVE-2010-1044 · HIGH 7.5 · 2010-03-23CVE-2009-4387 · MEDIUM 4.3 · 2009-12-23CVE-2009-3903 · MEDIUM 4.3 · 2009-11-06CVE-2008-2797 · MEDIUM 4.3 · 2008-06-20CVE-2008-1775 · LOW 3.5 · 2008-04-14CVE-2008-1566 · MEDIUM 4.3 · 2008-04-01CVE-2008-1538 · MEDIUM 4.3 · 2008-03-28CVE-2008-1432 · MEDIUM 4.3 · 2008-03-20CVE-2008-1299 · MEDIUM 6.1 · 2008-03-12CVE-2008-0474 · MEDIUM 4.3 · 2008-01-30CVE-2008-0476 · MEDIUM 6.4 · 2008-01-30CVE-2008-0475 · MEDIUM 5.0 · 2008-01-30CVE-2007-5891 · MEDIUM 4.3 · 2007-11-08CVE-2007-3594 · LOW 2.6 · 2007-07-06CVE-2007-3593 · MEDIUM 4.3 · 2007-07-06CVE-2007-2429 · HIGH 10.0 · 2007-05-02CVE-2007-1642 · MEDIUM 4.0 · 2007-03-24CVE-2006-2343 · MEDIUM 5.8 · 2006-05-12CVE-2005-3522 · MEDIUM 4.3 · 2005-11-06

Known CVEs (100)About this listSourced from the public NVD database, matched by vendor name. This is a name-based match, not exact version tracking — always check the linked NVD record for affected versions before drawing conclusions. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2017-16847 ↗CRITICAL 9.82017

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.

  • CVE-2017-16846 ↗CRITICAL 9.82017

    Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.

  • CVE-2017-11512 ↗HIGH 7.52017

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticate…

  • CVE-2017-11511 ↗HIGH 7.52017

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticate…

  • CVE-2017-16543 ↗CRITICAL 9.82017

    Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.

  • CVE-2017-16542 ↗HIGH 8.82017

    Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

  • CVE-2015-8249 ↗CRITICAL 9.82017

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

  • CVE-2017-14123 ↗HIGH 8.82017

    Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the serve…

  • CVE-2015-9107 ↗CRITICAL 9.82017

    Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or…

  • CVE-2017-11687 ↗MEDIUM 6.12017

    Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitra…

  • CVE-2017-11686 ↗MEDIUM 6.12017

    Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the pa…

  • CVE-2017-11685 ↗MEDIUM 6.12017

    Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web …

  • CVE-2017-11346 ↗CRITICAL 9.82017

    Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

  • CVE-2015-7781 ↗HIGH 7.52017

    ManageEngine Firewall Analyzer before 8.0 does not restrict access permissions.

  • CVE-2015-7780 ↗MEDIUM 6.52017

    Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.

  • CVE-2017-7213 ↗CRITICAL 10.02017

    Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

  • CVE-2016-1161 ↗HIGH 8.02017

    Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).

  • CVE-2016-4890 ↗MEDIUM 5.32017

    ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a coo…

  • CVE-2016-4889 ↗HIGH 8.82017

    ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

  • CVE-2016-4888 ↗MEDIUM 5.42017

    Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • …and 80 more

Competitors (12)

full alternatives comparison →
1PasswordAbbey LabsAbsoluteAceissAcronis International GmbHActifileArray NetworksBroadcomDBAPP SecurityPalo Alto NetworksRepacketSOFTwarfare

Products (5)

Identity & Access Management

3
  • ManageEngine AD360AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Integrated IAM suite for Active Directory and hybrid identity management
  • ManageEngine ADManager PlusAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Unified AD and Microsoft 365 mgmt, reporting, and automation platform
  • ManageEngine Identity360AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Cloud-based IAM platform for identity mgmt, SSO, MFA, and lifecycle mgmt

Network Detection & Response (NDR)

1
  • ManageEngine NetFlow AnalyzerAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Flow-based network traffic monitoring and bandwidth analysis tool

Data Loss Prevention

1
  • ManageEngine Endpoint DLP PlusAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →source ↗
    Endpoint DLP solution for detecting, classifying, and controlling sensitive data