In Zoho ManageEngine Applications Manager versions 14710 and earlier, an authenticated admin user can upload a malicious JAR file to a specific location on the server. This allows the attacker to execute arbitrary code with the privileges of the application, resulting in remote code execution (RCE). The vulnerability arises from insufficient validation of uploaded JAR files by the application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This two-file standalone repository contains a Python 3 exploit (CVE-2020-14008.py) and supporting README for authenticated remote code execution against ManageEngine Applications Manager versions up to 14720. The script authenticates to the web console, retrieves the application installation directory, creates an Execute Program Action via adminAction.do, executes that action, and removes it afterward. Its default cmd mode generates shell.ps1, launches an embedded HTTP server to host it, and instructs the Windows target to download and execute the PowerShell reverse-shell payload. Callback host, listener port, HTTP port, target URL/port, and credentials are configurable through CLI arguments. An alternate jar mode implements the older Exploit-DB 48793 chain involving malicious WebLogic JAR upload, placement, and credential-test-triggered class loading. The implementation disables TLS certificate verification and uses requests and lxml; it is an operational exploit rather than a detection-only utility.
This two-file repository contains a Python 3 exploit script and supporting README for CVE-2020-14008, an authenticated remote-code-execution issue affecting ManageEngine Applications Manager through version 14720. The main script uses requests and lxml to establish an authenticated administrative session, query the product's installation directory, create an Execute Program Action through adminAction.do, trigger that task through executeScript.do, and delete it afterward. In its default cmd mode, it generates shell.ps1 locally, starts an embedded HTTP server, and configures the target to download and execute that PowerShell payload, producing a reverse shell to operator-provided host and port. An optional jar mode retains the older Exploit-DB 48793 approach involving a malicious WebLogic JAR and requires javac and jar. The repository is standalone rather than a known exploit framework module; its payload and target/callback values are operator-configurable through CLI arguments.
This five-file repository contains two Python 3 exploit scripts, a README, license, and gitignore. The main entry point, am_rce_cmd.py, imports helper routines from cve-2020-14008.py and implements a more direct authenticated exploitation route for CVE-2020-14008. It obtains an initial session, logs into Applications Manager, queries server information to identify the installation directory, creates an Execute Program Action through /adminAction.do using createExecProgAction, executes it, and removes the action afterward. The created action launches PowerShell with execution-policy bypass and hidden-window options, downloading shell.ps1 from an attacker HTTP server. shell.ps1 is generated locally with the chosen callback host and port and provides an interactive TCP PowerShell reverse shell. The supplied defaults identify a private lab target at 192.168.113.95:8443 and an operator host at 192.168.45.224, but target, callback, reverse-shell, Applications Manager, and HTTP-server ports can be supplied as arguments. The direct script uses admin/admin by default and disables TLS certificate verification. It is therefore an authenticated RCE tool, rather than a scanner or detection utility. The retained cve-2020-14008.py is the original Exploit-DB-style PoC. In contrast to the primary script, it constructs a malicious Java class in a weblogic.jndi.Environment package, builds a JAR, attempts to upload/place weblogic.jar under classes/weblogic/version8/, and triggers a WebLogic credential test to load the planted class and establish a command shell. The README explicitly describes this older upload/classloader sequence as unreliable and positions am_rce_cmd.py as its replacement.
This repository is a small standalone exploit repo containing a README and one Python exploit script, cve-2020-14008.py. It targets CVE-2020-14008 in Zoho ManageEngine Applications Manager <= 14720 and is a real authenticated RCE exploit rather than a detector. The script logs into the web application using supplied admin credentials, retrieves session cookies, queries /common/serverinfo.do to discover the installation directory, locally generates and compiles a malicious Java class named weblogic.jndi.Environment into weblogic.jar, uploads that JAR into the WebLogic library path expected by the application, and then triggers the vulnerable Weblogic credential test so the application loads the attacker-controlled class. The exploit’s main capability is remote code execution with a reverse shell payload. The generated Java payload uses ProcessBuilder to launch cmd.exe and connects back to an attacker-specified host and port over a raw socket, effectively providing an interactive shell. The README states the resulting privileges are SYSTEM-level on affected Windows deployments. The script includes a fallback path: if direct upload/path traversal to classes/weblogic/version8/ does not work, it creates a scheduled task/action to move the uploaded JAR from a working directory into the required location, executes that task, deletes it, and then triggers the credential test. Repository structure is minimal: README.md documents the vulnerability, prerequisites, usage, exploit flow, and references; cve-2020-14008.py contains the full exploit logic and also dynamically writes Java source code used as the payload. Languages present are primarily Python, with embedded/generated Java. Operationally, this is beyond a bare PoC because it automates authentication, environment discovery, payload generation, upload, fallback tasking, and trigger execution, but it is still a standalone script with a basic hardcoded reverse-shell approach rather than a reusable framework module.
This repository contains a Python exploit script (exploit.py) and a README.md for CVE-2020-14008, a deserialization vulnerability in ManageEngine Applications Manager. The exploit authenticates to the target using provided credentials, then sends a specially crafted payload to the /RestAPI/LogReceiver endpoint, leveraging Java deserialization to execute a base64-encoded PowerShell reverse shell. The attacker must run a netcat listener to receive the shell, which runs with SYSTEM privileges, granting full control over the target server. The exploit is operational, requiring valid credentials and network access to the target. The repository is well-structured, with clear usage instructions and a single Python exploit file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.