Known vulnerabilities in Zoho ManageEngine SupportCenter Plus 11005
Vendor:
Zoho Corporation
Software:
Zoho ManageEngine SupportCenter Plus
Version:
11005
Software CPE:
cpe:2.3:a:zohocorp:zoho_manageengine_supportcenter_plus:*:*:*:*:*:*:*:*
Website:
https://www.zohocorp.com/index.html
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Vulnerabilities by Severity
15150
15140
15110
14950
14850
14940
14930
14920
14910
14900
14840
14830
14820
14810
14800
14730
14720
14710
14700
14620
14610
14600
14507
14506
14505
14504
14503
14502
14501
14500
14305
14304
14303
14302
14201
14301
14300
14200
14001
14000
11027
11026
11025
11024
11023
11022
11021
11020
11019
11014
11013
11012
11011
11010
11009
11008
11007
11006
11005
11004
11003
11002
11001
11000
11016
11015
11018
11017
-
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU69880 - Permissions, Privileges, and Access Controls CVE-2022-40773 |
CWE-264 | Medium | 11025 | 05.12.2022 |
SB2022120535 |
||
| #VU69872 - Permissions, Privileges, and Access Controls CVE-2022-40772 |
CWE-264 | Medium | 11025 | 05.12.2022 |
SB2022120535 |
||
| #VU69580 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2022-40771 |
CWE-611 | Low | 11026 | 24.11.2022 |
SB2022112419 SB2022112420 SB2022112421 |
||
| #VU69556 - Command injection CVE-2022-40770 |
CWE-77 | Low | 11026 | 24.11.2022 |
SB2022112404 SB2022112405 SB2022112406 |