Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
https://www.manageengine.com/products/applications_manager/issues.html#14730