9.8

CVE-2020-21642

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2900
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2901
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2902
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2903
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2904
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2905
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2906
Zohocorp ≫ Manageengine Analytics Plus Version 2.9 Update build2907
Zohocorp ≫ Manageengine Analytics Plus Version 3.0 Update build3000
Zohocorp ≫ Manageengine Analytics Plus Version 3.0 Update build3010
Zohocorp ≫ Manageengine Analytics Plus Version 3.0 Update build3020
Zohocorp ≫ Manageengine Analytics Plus Version 3.0 Update build3030
Zohocorp ≫ Manageengine Analytics Plus Version 3.0 Update build3040
Zohocorp ≫ Manageengine Analytics Plus Version 3.0 Update build3050
Zohocorp ≫ Manageengine Analytics Plus Version 3.1 Update build3100
Zohocorp ≫ Manageengine Analytics Plus Version 3.1 Update build3110
Zohocorp ≫ Manageengine Analytics Plus Version 3.1 Update build3120
Zohocorp ≫ Manageengine Analytics Plus Version 3.1 Update build3130
Zohocorp ≫ Manageengine Analytics Plus Version 3.1 Update build3140
Zohocorp ≫ Manageengine Analytics Plus Version 3.2 Update build3200
Zohocorp ≫ Manageengine Analytics Plus Version 3.2 Update build3250
Zohocorp ≫ Manageengine Analytics Plus Version 3.3 Update build3300
Zohocorp ≫ Manageengine Analytics Plus Version 3.3 Update build3310
Zohocorp ≫ Manageengine Analytics Plus Version 3.4 Update build3400
Zohocorp ≫ Manageengine Analytics Plus Version 3.4 Update build3450
Zohocorp ≫ Manageengine Analytics Plus Version 3.5 Update build3500
Zohocorp ≫ Manageengine Analytics Plus Version 3.6 Update build3600
Zohocorp ≫ Manageengine Analytics Plus Version 3.7 Update build3700
Zohocorp ≫ Manageengine Analytics Plus Version 3.8 Update build3800
Zohocorp ≫ Manageengine Analytics Plus Version 3.9 Update build3900
Zohocorp ≫ Manageengine Analytics Plus Version 3.9 Update build3950
Zohocorp ≫ Manageengine Analytics Plus Version 4.0 Update build4000
Zohocorp ≫ Manageengine Analytics Plus Version 4.1 Update build4100
Zohocorp ≫ Manageengine Analytics Plus Version 4.1 Update build4150
Zohocorp ≫ Manageengine Analytics Plus Version 4.2 Update build4200
Zohocorp ≫ Manageengine Analytics Plus Version 4.2 Update build4250
Zohocorp ≫ Manageengine Analytics Plus Version 4.2 Update build4260
Zohocorp ≫ Manageengine Analytics Plus Version 4.2 Update build4270
Zohocorp ≫ Manageengine Analytics Plus Version 4.2 Update build4280
Zohocorp ≫ Manageengine Analytics Plus Version 4.3 Update build4300
Zohocorp ≫ Manageengine Analytics Plus Version 4.3 Update build4310
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6.82% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://www.manageengine.com/analytics-plus/release-notes.html
Vendor Advisory
Release Notes