7.8

CVE-2021-44652

Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update -
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4400
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4401
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4402
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4403
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4406
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4407
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4408
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4410
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4411
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4412
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4413
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4414
Zohocorp ≫ Manageengine O365 Manager Plus Version 4.4 Update build4415
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.57% 0.831
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.manageengine.com/microsoft-365-management-reporting/release-notes.html?Build=4416
Vendor Advisory