Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Status: PUBLISHED
Assigner: mitre
Published: 2020-03-06T16:05:22.000Z
Updated: 2025-10-21T23:35:49.767Z
Reserved: 2020-03-06T00:00:00.000Z
Link: CVE-2020-10189
Updated: 2024-08-04T10:58:39.095Z
Status : Modified
Published: 2020-03-06T17:15:12.383
Modified: 2025-10-22T00:16:54.337
Link: CVE-2020-10189
No data.