CVE-2020-24786

An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
zohocorpmanageengine_adselfservice_plus
𝑥
≤ 5.7
zohocorpmanageengine_adselfservice_plus
5.8
zohocorpmanageengine_adselfservice_plus
5.8:5800
zohocorpmanageengine_adselfservice_plus
5.8:5801
zohocorpmanageengine_adselfservice_plus
5.8:5802
zohocorpmanageengine_adselfservice_plus
5.8:5803
zohocorpmanageengine_adselfservice_plus
5.8:5804
zohocorpmanageengine_adselfservice_plus
5.8:5805
zohocorpmanageengine_adselfservice_plus
5.8:5806
zohocorpmanageengine_adselfservice_plus
5.8:5807
zohocorpmanageengine_adselfservice_plus
5.8:5808
zohocorpmanageengine_adselfservice_plus
5.8:5809
zohocorpmanageengine_adselfservice_plus
5.8:5810
zohocorpmanageengine_adselfservice_plus
5.8:5811
zohocorpmanageengine_adselfservice_plus
5.8:5812
zohocorpmanageengine_adselfservice_plus
5.8:5813
zohocorpmanageengine_adselfservice_plus
5.8:5814
zohocorpmanageengine_adselfservice_plus
5.8:5815
zohocorpmanageengine_adselfservice_plus
5.8:5816
zohocorpmanageengine_exchange_reporter_plus
𝑥
≤ 5.4
zohocorpmanageengine_exchange_reporter_plus
5.5:5500
zohocorpmanageengine_exchange_reporter_plus
5.5:5501
zohocorpmanageengine_exchange_reporter_plus
5.5:5502
zohocorpmanageengine_exchange_reporter_plus
5.5:5503
zohocorpmanageengine_exchange_reporter_plus
5.5:5504
zohocorpmanageengine_ad360
𝑥
≤ 4.1
zohocorpmanageengine_ad360
4.2:4200
zohocorpmanageengine_ad360
4.2:4201
zohocorpmanageengine_ad360
4.2:4202
zohocorpmanageengine_ad360
4.2:4203
zohocorpmanageengine_ad360
4.2:4204
zohocorpmanageengine_ad360
4.2:4205
zohocorpmanageengine_ad360
4.2:4206
zohocorpmanageengine_ad360
4.2:4207
zohocorpmanageengine_ad360
4.2:4208
zohocorpmanageengine_ad360
4.2:4209
zohocorpmanageengine_ad360
4.2:4210
zohocorpmanageengine_ad360
4.2:4212
zohocorpmanageengine_ad360
4.2:4213
zohocorpmanageengine_ad360
4.2:4214
zohocorpmanageengine_ad360
4.2:4215
zohocorpmanageengine_ad360
4.2:4216
zohocorpmanageengine_ad360
4.2:4217
zohocorpmanageengine_ad360
4.2:4219
zohocorpmanageengine_ad360
4.2:4220
zohocorpmanageengine_ad360
4.2:4222
zohocorpmanageengine_ad360
4.2:4223
zohocorpmanageengine_ad360
4.2:4224
zohocorpmanageengine_ad360
4.2:4225
zohocorpmanageengine_ad360
4.2:4227
zohocorpmanageengine_datasecurity_plus
𝑥
≤ 5.0
zohocorpmanageengine_datasecurity_plus
6.0:6000
zohocorpmanageengine_datasecurity_plus
6.0:6001
zohocorpmanageengine_datasecurity_plus
6.0:6002
zohocorpmanageengine_datasecurity_plus
6.0:6003
zohocorpmanageengine_datasecurity_plus
6.0:6010
zohocorpmanageengine_datasecurity_plus
6.0:6011
zohocorpmanageengine_datasecurity_plus
6.0:6012
zohocorpmanageengine_datasecurity_plus
6.0:6013
zohocorpmanageengine_datasecurity_plus
6.0:6020
zohocorpmanageengine_datasecurity_plus
6.0:6021
zohocorpmanageengine_datasecurity_plus
6.0:6030
zohocorpmanageengine_datasecurity_plus
6.0:6031
zohocorpmanageengine_datasecurity_plus
6.0:6032
zohocorpmanageengine_recovermanager_plus
𝑥
≤ 5.4
zohocorpmanageengine_recovermanager_plus
6.0:6001
zohocorpmanageengine_recovermanager_plus
6.0:6003
zohocorpmanageengine_recovermanager_plus
6.0:6005
zohocorpmanageengine_recovermanager_plus
6.0:6011
zohocorpmanageengine_recovermanager_plus
6.0:6016
zohocorpmanageengine_eventlog_analyzer
𝑥
≤ 12.1.2
zohocorpmanageengine_eventlog_analyzer
12.1.3:12130
zohocorpmanageengine_eventlog_analyzer
12.1.3:12135
zohocorpmanageengine_adaudit_plus
𝑥
≤ 5.1
zohocorpmanageengine_adaudit_plus
6.0:6000
zohocorpmanageengine_adaudit_plus
6.0:6001
zohocorpmanageengine_adaudit_plus
6.0:6002
zohocorpmanageengine_adaudit_plus
6.0:6003
zohocorpmanageengine_adaudit_plus
6.0:6010
zohocorpmanageengine_adaudit_plus
6.0:6030
zohocorpmanageengine_adaudit_plus
6.0:6031
zohocorpmanageengine_adaudit_plus
6.0:6032
zohocorpmanageengine_adaudit_plus
6.0:6033
zohocorpmanageengine_adaudit_plus
6.0:6050
zohocorpmanageengine_adaudit_plus
6.0:6052
zohocorpmanageengine_o365_manager_plus
𝑥
≤ 4.2
zohocorpmanageengine_o365_manager_plus
4.3:4300
zohocorpmanageengine_o365_manager_plus
4.3:4301
zohocorpmanageengine_o365_manager_plus
4.3:4302
zohocorpmanageengine_o365_manager_plus
4.3:4303
zohocorpmanageengine_o365_manager_plus
4.3:4304
zohocorpmanageengine_o365_manager_plus
4.3:4305
zohocorpmanageengine_o365_manager_plus
4.3:4306
zohocorpmanageengine_o365_manager_plus
4.3:4308
zohocorpmanageengine_o365_manager_plus
4.3:4309
zohocorpmanageengine_o365_manager_plus
4.3:4310
zohocorpmanageengine_o365_manager_plus
4.3:4311
zohocorpmanageengine_o365_manager_plus
4.3:4312
zohocorpmanageengine_o365_manager_plus
4.3:4316
zohocorpmanageengine_o365_manager_plus
4.3:4317
zohocorpmanageengine_o365_manager_plus
4.3:4318
zohocorpmanageengine_o365_manager_plus
4.3:4319
zohocorpmanageengine_o365_manager_plus
4.3:4320
zohocorpmanageengine_o365_manager_plus
4.3:4321
zohocorpmanageengine_o365_manager_plus
4.3:4322
zohocorpmanageengine_o365_manager_plus
4.3:4324
zohocorpmanageengine_o365_manager_plus
4.3:4325
zohocorpmanageengine_o365_manager_plus
4.3:4327
zohocorpmanageengine_o365_manager_plus
4.3:4328
zohocorpmanageengine_o365_manager_plus
4.3:4329
zohocorpmanageengine_o365_manager_plus
4.3:4330
zohocorpmanageengine_o365_manager_plus
4.3:4331
zohocorpmanageengine_o365_manager_plus
4.3:4332
zohocorpmanageengine_o365_manager_plus
4.3:4333
zohocorpmanageengine_o365_manager_plus
4.3:4334
zohocorpmanageengine_cloud_security_plus
𝑥
≤ 4.0
zohocorpmanageengine_cloud_security_plus
4.1:4100
zohocorpmanageengine_cloud_security_plus
4.1:4101
zohocorpmanageengine_cloud_security_plus
4.1:4102
zohocorpmanageengine_cloud_security_plus
4.1:4103
zohocorpmanageengine_cloud_security_plus
4.1:4104
zohocorpmanageengine_cloud_security_plus
4.1:4105
zohocorpmanageengine_cloud_security_plus
4.1:4106
zohocorpmanageengine_cloud_security_plus
4.1:4107
zohocorpmanageengine_cloud_security_plus
4.1:4108
zohocorpmanageengine_cloud_security_plus
4.1:4109
zohocorpmanageengine_admanager_plus
𝑥
≤ 6.6
zohocorpmanageengine_admanager_plus
7.0:7000
zohocorpmanageengine_admanager_plus
7.0:7010
zohocorpmanageengine_admanager_plus
7.0:7011
zohocorpmanageengine_admanager_plus
7.0:7020
zohocorpmanageengine_admanager_plus
7.0:7030
zohocorpmanageengine_admanager_plus
7.0:7040
zohocorpmanageengine_admanager_plus
7.0:7041
zohocorpmanageengine_admanager_plus
7.0:7050
zohocorpmanageengine_admanager_plus
7.0:7051
zohocorpmanageengine_admanager_plus
7.0:7052
zohocorpmanageengine_admanager_plus
7.0:7053
zohocorpmanageengine_admanager_plus
7.0:7054
zohocorpmanageengine_log360
𝑥
≤ 5.0
zohocorpmanageengine_log360
5.1:5100
zohocorpmanageengine_log360
5.1:5102
zohocorpmanageengine_log360
5.1:5107
zohocorpmanageengine_log360
5.1:5108
zohocorpmanageengine_log360
5.1:5110
zohocorpmanageengine_log360
5.1:5111
zohocorpmanageengine_log360
5.1:5120
zohocorpmanageengine_log360
5.1:5150
zohocorpmanageengine_log360
5.1:5154
zohocorpmanageengine_log360
5.1:5155
zohocorpmanageengine_log360
5.1:5160
zohocorpmanageengine_log360
5.1:5164
𝑥
= Vulnerable software versions
References