Multiple Zoho ManageEngine on-premise products, such as...
Critical severity
Unreviewed
Published
Jan 18, 2023
to the GitHub Advisory Database
•
Updated Sep 13, 2024
Description
Published by the National Vulnerability Database
Jan 18, 2023
Published to the GitHub Advisory Database
Jan 18, 2023
Last updated
Sep 13, 2024
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections.
References