10
CVSSv2

CVE-2020-24786

Published: 31/08/2020 Updated: 07/11/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine adselfservice plus 5.8

zohocorp manageengine adselfservice plus

zohocorp manageengine exchange reporter plus

zohocorp manageengine exchange reporter plus 5.5

zohocorp manageengine ad360

zohocorp manageengine ad360 4.2

zohocorp manageengine datasecurity plus

zohocorp manageengine datasecurity plus 6.0

zohocorp manageengine recovermanager plus

zohocorp manageengine recovermanager plus 6.0

zohocorp manageengine eventlog analyzer 12.1.3

zohocorp manageengine eventlog analyzer

zohocorp manageengine adaudit plus

zohocorp manageengine adaudit plus 6.0

zohocorp manageengine o365 manager plus 4.3

zohocorp manageengine o365 manager plus

zohocorp manageengine cloud security plus

zohocorp manageengine cloud security plus 4.1

zohocorp manageengine admanager plus

zohocorp manageengine admanager plus 7.0

zohocorp manageengine log360

zohocorp manageengine log360 5.1