CVE-2020-10816

Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
zohocorpmanageengine_applications_manager
14.7
zohocorpmanageengine_applications_manager
14.7:build14700
zohocorpmanageengine_applications_manager
14.7:build14710
zohocorpmanageengine_applications_manager
14.7:build14720
zohocorpmanageengine_applications_manager
14.7:build14730
zohocorpmanageengine_applications_manager
14.7:build14740
zohocorpmanageengine_applications_manager
14.7:build14750
zohocorpmanageengine_applications_manager
14.7:build14760
zohocorpmanageengine_applications_manager
14.7:build14770
zohocorpmanageengine_applications_manager
14.7:build14780
𝑥
= Vulnerable software versions