7.5

CVE-2020-11527

In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Opmanager Version < 12.4
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update -
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124000
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124011
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124012
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124013
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124014
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124015
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124016
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124022
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124023
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124024
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124025
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124026
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124027
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124030
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124033
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124037
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124039
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124040
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124041
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124042
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124043
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124051
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124053
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124054
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124056
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124058
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124065
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124066
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124067
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124069
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124070
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124071
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124074
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124075
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124081
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124082
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124085
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124086
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124087
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124089
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124095
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124096
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124097
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124098
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124099
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124100
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124101
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124102
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124168
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124169
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124175
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124176
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124178
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.48% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.manageengine.com/network-monitoring/help/read-me-complete.html#124181
Vendor Advisory