Site icon Segurança Informática

Multiple zero-day vulnerabilities found in ManageEngine products

netflow_patch

Digital Defense uncovered multiple, previously undisclosed vulnerabilities within several Zoho ManageEngine products.

ManageEngine offers more than 90 tools to help manage IT operations, including networks, servers, applications, service desk, Active Directory, security, desktops, and mobile devices. Currently, the company claims to have more than 40,000 customers, including three out of every five Fortune 500 company.

 

Vulnerability impact

The discovered vulnerabilities allow unauthenticated file upload, blind SQL injection, authenticated remote code execution and user enumeration, potentially revealing sensitive information or full compromise of the application.

 

Did you like what you read? Don’t miss any more posts by subscribing our newsletter now!

 

 

Affected applications include ServiceDesk Plus, Service Plus MSP, OpManager, Firewall Analyzer, Network Configuration Manager, OpUtils and NetFlow Analyzer.

Summary:

Zoho ManageEngine has addressed the vulnerabilities and is making patches available for each of the affected applications.

 

Exit mobile version