VulnerabilityModified
CVE-2020-35765
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
HIGH 8.8EPSS 27.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 27.35% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- zohocorp/manageengine applications manager
- Source
- cve@mitre.org
References
- https://www.manageengine.comVendor Advisory
- https://www.manageengine.com/products/applications_manager/issues.html#v15000Release Notes, Vendor Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2020-35765.htmlVendor Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
- https://www.manageengine.comVendor Advisory
- https://www.manageengine.com/products/applications_manager/issues.html#v15000Release Notes, Vendor Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2020-35765.htmlVendor Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
- https://www.tenable.com/security/research/tra-2021-02Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.