Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_applications_manager | Zohocorp | 14.0 (including) | 14.0 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14000 (including) | 14.0-build14000 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14010 (including) | 14.0-build14010 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14020 (including) | 14.0-build14020 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14030 (including) | 14.0-build14030 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14040 (including) | 14.0-build14040 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14050 (including) | 14.0-build14050 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14060 (including) | 14.0-build14060 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14070 (including) | 14.0-build14070 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14071 (including) | 14.0-build14071 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14072 (including) | 14.0-build14072 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14073 (including) | 14.0-build14073 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14080 (including) | 14.0-build14080 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14090 (including) | 14.0-build14090 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14100 (including) | 14.0-build14100 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14110 (including) | 14.0-build14110 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14120 (including) | 14.0-build14120 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14130 (including) | 14.0-build14130 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14140 (including) | 14.0-build14140 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14150 (including) | 14.0-build14150 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14160 (including) | 14.0-build14160 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14170 (including) | 14.0-build14170 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14180 (including) | 14.0-build14180 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14190 (including) | 14.0-build14190 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14200 (including) | 14.0-build14200 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14210 (including) | 14.0-build14210 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14220 (including) | 14.0-build14220 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14230 (including) | 14.0-build14230 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14240 (including) | 14.0-build14240 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14250 (including) | 14.0-build14250 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14260 (including) | 14.0-build14260 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14261 (including) | 14.0-build14261 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14262 (including) | 14.0-build14262 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14270 (including) | 14.0-build14270 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14280 (including) | 14.0-build14280 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14290 (including) | 14.0-build14290 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14300 (including) | 14.0-build14300 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14310 (including) | 14.0-build14310 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14330 (including) | 14.0-build14330 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14331 (including) | 14.0-build14331 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14332 (including) | 14.0-build14332 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14340 (including) | 14.0-build14340 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14350 (including) | 14.0-build14350 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14360 (including) | 14.0-build14360 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14361 (including) | 14.0-build14361 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14370 (including) | 14.0-build14370 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14380 (including) | 14.0-build14380 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14390 (including) | 14.0-build14390 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14400 (including) | 14.0-build14400 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14401 (including) | 14.0-build14401 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14410 (including) | 14.0-build14410 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14420 (including) | 14.0-build14420 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14430 (including) | 14.0-build14430 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14440 (including) | 14.0-build14440 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14450 (including) | 14.0-build14450 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14460 (including) | 14.0-build14460 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14470 (including) | 14.0-build14470 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14480 (including) | 14.0-build14480 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14490 (including) | 14.0-build14490 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14500 (including) | 14.0-build14500 (including) |
Manageengine_applications_manager | Zohocorp | 14.0-build14510 (including) | 14.0-build14510 (including) |
As data is migrated to the cloud, if access does not require authentication, it can be easier for attackers to access the data from anywhere on the Internet.