9.8

CVE-2020-21642

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2900
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2901
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2902
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2903
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2904
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2905
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2906
ZohocorpManageengine Analytics Plus Version2.9 Updatebuild2907
ZohocorpManageengine Analytics Plus Version3.0 Updatebuild3000
ZohocorpManageengine Analytics Plus Version3.0 Updatebuild3010
ZohocorpManageengine Analytics Plus Version3.0 Updatebuild3020
ZohocorpManageengine Analytics Plus Version3.0 Updatebuild3030
ZohocorpManageengine Analytics Plus Version3.0 Updatebuild3040
ZohocorpManageengine Analytics Plus Version3.0 Updatebuild3050
ZohocorpManageengine Analytics Plus Version3.1 Updatebuild3100
ZohocorpManageengine Analytics Plus Version3.1 Updatebuild3110
ZohocorpManageengine Analytics Plus Version3.1 Updatebuild3120
ZohocorpManageengine Analytics Plus Version3.1 Updatebuild3130
ZohocorpManageengine Analytics Plus Version3.1 Updatebuild3140
ZohocorpManageengine Analytics Plus Version3.2 Updatebuild3200
ZohocorpManageengine Analytics Plus Version3.2 Updatebuild3250
ZohocorpManageengine Analytics Plus Version3.3 Updatebuild3300
ZohocorpManageengine Analytics Plus Version3.3 Updatebuild3310
ZohocorpManageengine Analytics Plus Version3.4 Updatebuild3400
ZohocorpManageengine Analytics Plus Version3.4 Updatebuild3450
ZohocorpManageengine Analytics Plus Version3.5 Updatebuild3500
ZohocorpManageengine Analytics Plus Version3.6 Updatebuild3600
ZohocorpManageengine Analytics Plus Version3.7 Updatebuild3700
ZohocorpManageengine Analytics Plus Version3.8 Updatebuild3800
ZohocorpManageengine Analytics Plus Version3.9 Updatebuild3900
ZohocorpManageengine Analytics Plus Version3.9 Updatebuild3950
ZohocorpManageengine Analytics Plus Version4.0 Updatebuild4000
ZohocorpManageengine Analytics Plus Version4.1 Updatebuild4100
ZohocorpManageengine Analytics Plus Version4.1 Updatebuild4150
ZohocorpManageengine Analytics Plus Version4.2 Updatebuild4200
ZohocorpManageengine Analytics Plus Version4.2 Updatebuild4250
ZohocorpManageengine Analytics Plus Version4.2 Updatebuild4260
ZohocorpManageengine Analytics Plus Version4.2 Updatebuild4270
ZohocorpManageengine Analytics Plus Version4.2 Updatebuild4280
ZohocorpManageengine Analytics Plus Version4.3 Updatebuild4300
ZohocorpManageengine Analytics Plus Version4.3 Updatebuild4310
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 7.11% 0.911
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.