CVE-2017-16542: Zohocorp ManageEngine Applications Manager

High severity, CVSS 8.8. EPSS: 5.5% chance of exploitation in the next 30 days.

Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

Affected products

  • Zohocorp ManageEngine Applications Manager: version 13.0 only

Published 2017-11-05. Last modified 2026-06-17.