9.1

CVE-2023-47211

Exploit

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127000
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127101
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127130
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127131
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127187
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127244
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127257
ZohocorpManageengine Firewall Analyzer Version12.7 Updatebuild127259
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127000
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127003
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127101
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127130
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127131
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127187
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127244
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127255
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127257
ZohocorpManageengine Netflow Analyzer Version12.7 Updatebuild127259
ZohocorpManageengine Network Configuration Manager Version12.7 Updatebuild127000
ZohocorpManageengine Network Configuration Manager Version12.7 Updatebuild127102
ZohocorpManageengine Network Configuration Manager Version12.7 Updatebuild127105
ZohocorpManageengine Network Configuration Manager Version12.7 Updatebuild127132
ZohocorpManageengine Network Configuration Manager Version12.7 Updatebuild127243
ZohocorpManageengine Network Configuration Manager Version12.7 Updatebuild127257
ZohocorpManageengine Network Configuration Manager Version12.7 Updatebuild127259
ZohocorpManageengine Opmanager Version < 12.7
ZohocorpManageengine Opmanager Version12.7 Updatebuild127000
ZohocorpManageengine Opmanager Version12.7 Updatebuild127001
ZohocorpManageengine Opmanager Version12.7 Updatebuild127002
ZohocorpManageengine Opmanager Version12.7 Updatebuild127003
ZohocorpManageengine Opmanager Version12.7 Updatebuild127004
ZohocorpManageengine Opmanager Version12.7 Updatebuild127100
ZohocorpManageengine Opmanager Version12.7 Updatebuild127101
ZohocorpManageengine Opmanager Version12.7 Updatebuild127102
ZohocorpManageengine Opmanager Version12.7 Updatebuild127103
ZohocorpManageengine Opmanager Version12.7 Updatebuild127104
ZohocorpManageengine Opmanager Version12.7 Updatebuild127109
ZohocorpManageengine Opmanager Version12.7 Updatebuild127116
ZohocorpManageengine Opmanager Version12.7 Updatebuild127117
ZohocorpManageengine Opmanager Version12.7 Updatebuild127118
ZohocorpManageengine Opmanager Version12.7 Updatebuild127119
ZohocorpManageengine Opmanager Version12.7 Updatebuild127120
ZohocorpManageengine Opmanager Version12.7 Updatebuild127122
ZohocorpManageengine Opmanager Version12.7 Updatebuild127123
ZohocorpManageengine Opmanager Version12.7 Updatebuild127131
ZohocorpManageengine Opmanager Version12.7 Updatebuild127133
ZohocorpManageengine Opmanager Version12.7 Updatebuild127134
ZohocorpManageengine Opmanager Version12.7 Updatebuild127136
ZohocorpManageengine Opmanager Version12.7 Updatebuild127138
ZohocorpManageengine Opmanager Version12.7 Updatebuild127140
ZohocorpManageengine Opmanager Version12.7 Updatebuild127141
ZohocorpManageengine Opmanager Version12.7 Updatebuild127185
ZohocorpManageengine Opmanager Version12.7 Updatebuild127186
ZohocorpManageengine Opmanager Version12.7 Updatebuild127187
ZohocorpManageengine Opmanager Version12.7 Updatebuild127188
ZohocorpManageengine Opmanager Version12.7 Updatebuild127189
ZohocorpManageengine Opmanager Version12.7 Updatebuild127191
ZohocorpManageengine Opmanager Version12.7 Updatebuild127240
ZohocorpManageengine Opmanager Version12.7 Updatebuild127241
ZohocorpManageengine Opmanager Version12.7 Updatebuild127242
ZohocorpManageengine Opmanager Version12.7 Updatebuild127243
ZohocorpManageengine Opmanager Version12.7 Updatebuild127255
ZohocorpManageengine Opmanager Version12.7 Updatebuild127256
ZohocorpManageengine Opmanager Version12.7 Updatebuild127257
ZohocorpManageengine Opmanager Version12.7 Updatebuild127258
ZohocorpManageengine Opmanager Version12.7 Updatebuild127259
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127109
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127122
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127123
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127138
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127139
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127140
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127141
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127142
ZohocorpManageengine Opmanager Msp Version12.7 Updatebuild127259
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127109
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127122
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127123
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127138
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127139
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127140
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127141
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127142
ZohocorpManageengine Opmanager Plus Version12.7 Updatebuild127259
ZohocorpManageengine Oputils Version < 12.7
ZohocorpManageengine Oputils Version12.7 Updatebuild127101
ZohocorpManageengine Oputils Version12.7 Updatebuild127117
ZohocorpManageengine Oputils Version12.7 Updatebuild127134
ZohocorpManageengine Oputils Version12.7 Updatebuild127241
ZohocorpManageengine Oputils Version12.7 Updatebuild127242
ZohocorpManageengine Oputils Version12.7 Updatebuild127258
ZohocorpManageengine Oputils Version12.7 Updatebuild127259
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 84.43% 0.993
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
talos-cna@cisco.com 9.1 3.1 5.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.