Lucene search

K
cveMitreCVE-2023-28340
HistoryApr 11, 2023 - 1:15 a.m.

CVE-2023-28340

2023-04-1101:15:07
CWE-611
mitre
web.nvd.nist.gov
20
cve-2023-28340
zoho
manageengine
applications manager
xxe
vulnerability
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

45.4%

Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

Affected configurations

Nvd
Node
zohocorpmanageengine_applications_managerRange<16.3
OR
zohocorpmanageengine_applications_managerMatch16.3build16300
OR
zohocorpmanageengine_applications_managerMatch16.3build16310
OR
zohocorpmanageengine_applications_managerMatch16.3build16320
VendorProductVersionCPE
zohocorpmanageengine_applications_manager*cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16300:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16310:*:*:*:*:*:*
zohocorpmanageengine_applications_manager16.3cpe:2.3:a:zohocorp:manageengine_applications_manager:16.3:build16320:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

45.4%

Related for CVE-2023-28340