9.4

CVE-2021-20078

Exploit

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Opmanager Version < 12.5
ZohocorpManageengine Opmanager Version12.5 Updatebuild125000
ZohocorpManageengine Opmanager Version12.5 Updatebuild125002
ZohocorpManageengine Opmanager Version12.5 Updatebuild125100
ZohocorpManageengine Opmanager Version12.5 Updatebuild125101
ZohocorpManageengine Opmanager Version12.5 Updatebuild125102
ZohocorpManageengine Opmanager Version12.5 Updatebuild125108
ZohocorpManageengine Opmanager Version12.5 Updatebuild125110
ZohocorpManageengine Opmanager Version12.5 Updatebuild125111
ZohocorpManageengine Opmanager Version12.5 Updatebuild125112
ZohocorpManageengine Opmanager Version12.5 Updatebuild125113
ZohocorpManageengine Opmanager Version12.5 Updatebuild125114
ZohocorpManageengine Opmanager Version12.5 Updatebuild125116
ZohocorpManageengine Opmanager Version12.5 Updatebuild125117
ZohocorpManageengine Opmanager Version12.5 Updatebuild125118
ZohocorpManageengine Opmanager Version12.5 Updatebuild125120
ZohocorpManageengine Opmanager Version12.5 Updatebuild125121
ZohocorpManageengine Opmanager Version12.5 Updatebuild125123
ZohocorpManageengine Opmanager Version12.5 Updatebuild125124
ZohocorpManageengine Opmanager Version12.5 Updatebuild125125
ZohocorpManageengine Opmanager Version12.5 Updatebuild125136
ZohocorpManageengine Opmanager Version12.5 Updatebuild125137
ZohocorpManageengine Opmanager Version12.5 Updatebuild125139
ZohocorpManageengine Opmanager Version12.5 Updatebuild125140
ZohocorpManageengine Opmanager Version12.5 Updatebuild125143
ZohocorpManageengine Opmanager Version12.5 Updatebuild125144
ZohocorpManageengine Opmanager Version12.5 Updatebuild125145
ZohocorpManageengine Opmanager Version12.5 Updatebuild125156
ZohocorpManageengine Opmanager Version12.5 Updatebuild125157
ZohocorpManageengine Opmanager Version12.5 Updatebuild125158
ZohocorpManageengine Opmanager Version12.5 Updatebuild125159
ZohocorpManageengine Opmanager Version12.5 Updatebuild125161
ZohocorpManageengine Opmanager Version12.5 Updatebuild125163
ZohocorpManageengine Opmanager Version12.5 Updatebuild125174
ZohocorpManageengine Opmanager Version12.5 Updatebuild125175
ZohocorpManageengine Opmanager Version12.5 Updatebuild125176
ZohocorpManageengine Opmanager Version12.5 Updatebuild125177
ZohocorpManageengine Opmanager Version12.5 Updatebuild125178
ZohocorpManageengine Opmanager Version12.5 Updatebuild125180
ZohocorpManageengine Opmanager Version12.5 Updatebuild125181
ZohocorpManageengine Opmanager Version12.5 Updatebuild125192
ZohocorpManageengine Opmanager Version12.5 Updatebuild125193
ZohocorpManageengine Opmanager Version12.5 Updatebuild125194
ZohocorpManageengine Opmanager Version12.5 Updatebuild125195
ZohocorpManageengine Opmanager Version12.5 Updatebuild125196
ZohocorpManageengine Opmanager Version12.5 Updatebuild125197
ZohocorpManageengine Opmanager Version12.5 Updatebuild125198
ZohocorpManageengine Opmanager Version12.5 Updatebuild125201
ZohocorpManageengine Opmanager Version12.5 Updatebuild125204
ZohocorpManageengine Opmanager Version12.5 Updatebuild125212
ZohocorpManageengine Opmanager Version12.5 Updatebuild125213
ZohocorpManageengine Opmanager Version12.5 Updatebuild125214
ZohocorpManageengine Opmanager Version12.5 Updatebuild125215
ZohocorpManageengine Opmanager Version12.5 Updatebuild125216
ZohocorpManageengine Opmanager Version12.5 Updatebuild125228
ZohocorpManageengine Opmanager Version12.5 Updatebuild125229
ZohocorpManageengine Opmanager Version12.5 Updatebuild125230
ZohocorpManageengine Opmanager Version12.5 Updatebuild125231
ZohocorpManageengine Opmanager Version12.5 Updatebuild125232
ZohocorpManageengine Opmanager Version12.5 Updatebuild125233
ZohocorpManageengine Opmanager Version12.5 Updatebuild125312
ZohocorpManageengine Opmanager Version12.5 Updatebuild125323
ZohocorpManageengine Opmanager Version12.5 Updatebuild125324
ZohocorpManageengine Opmanager Version12.5 Updatebuild125326
ZohocorpManageengine Opmanager Version12.5 Updatebuild125328
ZohocorpManageengine Opmanager Version12.5 Updatebuild125329
ZohocorpManageengine Opmanager Version12.5 Updatebuild125340
ZohocorpManageengine Opmanager Version12.5 Updatebuild125341
ZohocorpManageengine Opmanager Version12.5 Updatebuild125342
ZohocorpManageengine Opmanager Version12.5 Updatebuild125343
ZohocorpManageengine Opmanager Version12.5 Updatebuild125344
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 44.11% 0.972
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvd@nist.gov 9.4 10 9.2
AV:N/AC:L/Au:N/C:N/I:C/A:C
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.