7.5
CVE-2021-37419
- EPSS 7.71%
- Published 21.09.2021 13:15:07
- Last modified 21.11.2024 06:15:07
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
Data is provided by the National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Admanager Plus Version < 6.1
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update-
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6100
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6101
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6102
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6103
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6104
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6105
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6106
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6107
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6108
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6109
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6110
Zohocorp ≫ Manageengine Admanager Plus Version6.1 Update6111
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 7.71% | 0.911 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.