Input validation error in ManageEngine Applications Manager - CVE-2017-11740
Published: May 23, 2019 / Updated: August 8, 2020
ManageEngine Applications Manager
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.