CVE-2020-10816

EUVD-2020-3222
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_applications_manager
14.7
zohocorpmanageengine_applications_manager
14.7:build14700
zohocorpmanageengine_applications_manager
14.7:build14710
zohocorpmanageengine_applications_manager
14.7:build14720
zohocorpmanageengine_applications_manager
14.7:build14730
zohocorpmanageengine_applications_manager
14.7:build14740
zohocorpmanageengine_applications_manager
14.7:build14750
zohocorpmanageengine_applications_manager
14.7:build14760
zohocorpmanageengine_applications_manager
14.7:build14770
zohocorpmanageengine_applications_manager
14.7:build14780
𝑥
= Vulnerable software versions