CVE-2020-15533: Zohocorp ManageEngine Applications Manager
Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
Affected products
- Zohocorp ManageEngine Applications Manager: before 14.6 (fixed in 14.6); version 14.6 only; version 14.7 only
Published 2020-10-01. Last modified 2026-06-17.