CVE-2020-21641: Zohocorp ManageEngine Analytics Plus

High severity, CVSS 7.5. EPSS: 4% chance of exploitation in the next 30 days.

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

Affected products

  • Zohocorp ManageEngine Analytics Plus: before 4.3.5 (fixed in 4.3.5)

Published 2022-08-15. Last modified 2026-06-17.