Zoho
No tracked subprocessors.
Documents
| Document | Verified | Changed | Evidence |
|---|---|---|---|
| Subprocessor list | snapshot | ||
| Privacy policy | snapshot | ||
| Terms | snapshot | ||
| Security page | snapshot | ||
| security.txt | snapshot | ||
| Status page | snapshot |
Subprocessors
None extracted.
Listed as a subprocessor by (4)
Purposes as each company states them.
BrightLocal brightlocal.com Email provision for brightlocal.ph
Rocket.Chat rocket.chat Business operations such as email marketing, newsletter, CRM, customer support (Zoho Desk); electronic document signing:
UserVoice uservoice.com
insightsoftware insightsoftware.com Website/API uptime monitoring and diagnostics
Security record
What public security catalogs list for Zoho, in their words.
Known exploited vulnerabilities
9 vulnerabilities in Zoho's software that CISA lists as exploited in the wild.
| CVE | Product | Vulnerability | Listed |
|---|---|---|---|
| CVE-2022-28810 | ManageEngine | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability | evidence |
| CVE-2022-47966 | ManageEngine | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability used by ransomware | evidence |
| CVE-2022-35405 | ManageEngine | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability | evidence |
| CVE-2021-44515 | Desktop Central | Zoho Desktop Central Authentication Bypass Vulnerability | evidence |
| CVE-2021-37415 | ManageEngine ServiceDesk Plus (SDP) | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability | evidence |
| CVE-2021-44077 | ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability | evidence |
| CVE-2019-8394 | ManageEngine | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability | evidence |
| CVE-2020-10189 | ManageEngine | Zoho ManageEngine Desktop Central File Upload Vulnerability | evidence |
| CVE-2021-40539 | ManageEngine | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability used by ransomware | evidence |
Federal contracts
By funding agency. UEI L23NME5SYMS1 failing
None found.
Prime awards and subawards reported by prime contractors. Purchases through a reseller name the reseller, not the vendor.
Changes
None since tracking began.