A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_applications_manager | Zohocorp | 13.7 (including) | 13.7 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13700 (including) | 13.7-build13700 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13710 (including) | 13.7-build13710 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13720 (including) | 13.7-build13720 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13730 (including) | 13.7-build13730 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13750 (including) | 13.7-build13750 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13760 (including) | 13.7-build13760 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13770 (including) | 13.7-build13770 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13780 (including) | 13.7-build13780 (including) |
Manageengine_applications_manager | Zohocorp | 13.7-build13790 (including) | 13.7-build13790 (including) |