Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LZohocorp Manageengine Servicedesk Plus
APPZohocorp14.8≤ 14.7Zohocorp Manageengine Servicedesk Plus Msp
APPZohocorp14.8≤ 14.7Zohocorp Manageengine Supportcenter Plus
APPZohocorp14.8≤ 14.7
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSS
Related vulnerabilities
CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
CVE-2021-44077CRITICAL9.8⚠ KEVPL ✓same product
Nieuwierzytelniony RCE w Zoho ManageEngine ServiceDesk Plus
CVE-2021-37415CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelnienia w REST API Zoho ManageEngine ServiceDesk Plus
CVE-2023-23076CRITICAL9.8PL ✓same product
Command injection w Zoho ManageEngine SupportCenter Plus 11 — tworzenie harmonogramów
CVE-2023-22964CRITICAL9.1PL ✓same product
Authentication Bypass w Zoho ManageEngine ServiceDesk Plus MSP (LDAP)