Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
https://github.com/0x0d3ad/CVE-2020-14008
https://github.com/JackHars/cve-2020-14008
https://www.manageengine.com/products/applications_manager/issues.html#14730