Third Party Index

Zoho

zoho.com

Transparency

Limited

Breakdown
Subprocessor listpublished; no entries could be read0 / 30
Processing locationsno list0 / 8
Purposesno list0 / 7
Data processing addendumnot found0 / 12
Trust centernot found0 / 8
Privacy policy6 / 6
security.txt6 / 6
Security page5 / 5
Status page5 / 5
Vulnerability disclosurenot found0 / 5
Pages still reachable8 / 8
Total30 / 100

Only documents we can retrieve count: a page behind a login or a broken link scores nothing.

Badge

Zoho transparency rating

For Zoho's own site; it updates with the rating.

<a href="https://thirdpartyindex.com/vendors/zoho"><img src="https://thirdpartyindex.com/badge/zoho.svg" alt="Zoho transparency rating on Third Party Index" height="20"></a>
[![Zoho transparency rating on Third Party Index](https://thirdpartyindex.com/badge/zoho.svg)](https://thirdpartyindex.com/vendors/zoho)

Documents

DocumentVerifiedChangedEvidence
Subprocessor list snapshot
Privacy policy snapshot
Terms snapshot
Security page snapshot
security.txt snapshot
Status page snapshot

Subprocessors

None extracted.

Listed as a subprocessor by (4)

Purposes as each company states them.

Security record

What public security catalogs list for Zoho, in their words.

Known exploited vulnerabilities

9 vulnerabilities in Zoho's software that CISA lists as exploited in the wild.

CVEProductVulnerabilityListed
CVE-2022-28810ManageEngineZoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability evidence
CVE-2022-47966ManageEngineZoho ManageEngine Multiple Products Remote Code Execution Vulnerability used by ransomware evidence
CVE-2022-35405ManageEngineZoho ManageEngine Multiple Products Remote Code Execution Vulnerability evidence
CVE-2021-44515Desktop CentralZoho Desktop Central Authentication Bypass Vulnerability evidence
CVE-2021-37415ManageEngine ServiceDesk Plus (SDP)Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability evidence
CVE-2021-44077ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusZoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability evidence
CVE-2019-8394ManageEngineZoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability evidence
CVE-2020-10189ManageEngineZoho ManageEngine Desktop Central File Upload Vulnerability evidence
CVE-2021-40539ManageEngineZoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability used by ransomware evidence

Source: CISA Known Exploited Vulnerabilities catalog.

Federal contracts

By funding agency. UEI L23NME5SYMS1 failing

None found.

Prime awards and subawards reported by prime contractors. Purchases through a reseller name the reseller, not the vendor.

Changes

None since tracking began.