ManageEngine operates a portfolio of IT management and administration tools including ServiceDesk Plus, Applications Manager, Desktop Central, and Password Manager Pro, many of which are deployed in security-critical roles across enterprises. The vendor's vulnerability footprint, though concentrated in a focused set of products, ranks among the more prominent in the landscape, reflecting the widespread adoption and administrative privileges these tools command. Vulnerabilities recur consistently through web-application and authentication layers—notably cross-site scripting, path traversal, SQL injection, sensitive information exposure, and improper authentication—reflecting the data-handling and access-control demands of centralized management platforms. The vendor's disclosures frequently acquire public exploit code, underscoring the appeal of administrative tools as targets for post-breach lateral movement and privilege escalation. Defenders should prioritize inventory and network segmentation for these products and treat their patch cycles as operationally urgent; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Manageengine over time
Signals from CVEs in this vendor scope (89 CVEs).
89 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5301HIGH Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. | Aug 28, 2017 | 8.8 | 84 | NO | YES |
CVE-2015-8249CRITICAL The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. | Sep 28, 2017 | 9.8 | 81 | NO | YES |
CVE-2017-11512HIGH The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot UR | Nov 8, 2017 | 7.5 | 78 | NO | YES |
CVE-2014-5377MEDIUM ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request. | Sep 4, 2014 | 5.0 | 69 | NO | YES |
CVE-2014-3996HIGH SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 9004 | Dec 5, 2014 | 7.5 | 56 | NO | YES |
CVE-2011-2757MEDIUM Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in th | Jul 17, 2011 | 5.0 | 55 | NO | YES |
CVE-2014-8499MEDIUM Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remot | Nov 17, 2014 | 6.5 | 52 | NO | YES |
CVE-2011-2755MEDIUM Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors | Jul 17, 2011 | 5.0 | 42 | NO | YES |
CVE-2024-24409HIGH Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. | Nov 8, 2024 | 8.8 | 39 | NO | YES |
CVE-2016-9488CRITICAL ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /ser | Jun 5, 2018 | 9.8 | 39 | NO | YES |
Signals from CVEs in this vendor scope (89 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Manageengine.
Media articles that mention a CVE ID that affects a product developed by Manageengine — matched by CVE ID, not by vendor name.