Remote Code Execution Vulnerability in Zoho ManageEngine Applications Manager
CVE-2020-10816
7.5HIGH
What is CVE-2020-10816?
Zoho ManageEngine Applications Manager versions up to 14780 are susceptible to a vulnerability that permits remote unauthenticated attackers to register managed servers through the AAMRequestProcessor servlet. This flaw can potentially lead to unauthorized access, thus compromising the application and its managed environments.
References
EPSS Score
30% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved