Lucene search

K
cve[email protected]CVE-2014-7866
HistoryDec 10, 2014 - 6:59 p.m.

CVE-2014-7866

2014-12-1018:59:00
CWE-22
web.nvd.nist.gov
29
cve-2014-7866
zoho manageengine
opmanager
directory traversal
vulnerability
nvd
it security

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.938 High

EPSS

Percentile

99.1%

Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a … (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.

Affected configurations

NVD
Node
zohocorpmanageengine_social_it_plusMatch11.0
Node
zohocorpmanageengine_it360Match10.3.0
OR
zohocorpmanageengine_it360Match10.4
Node
zohocorpmanageengine_opmanagerMatch8.8
OR
zohocorpmanageengine_opmanagerMatch9.0
OR
zohocorpmanageengine_opmanagerMatch9.1
OR
zohocorpmanageengine_opmanagerMatch9.2
OR
zohocorpmanageengine_opmanagerMatch9.4
OR
zohocorpmanageengine_opmanagerMatch10.0
OR
zohocorpmanageengine_opmanagerMatch10.1
OR
zohocorpmanageengine_opmanagerMatch10.2
OR
zohocorpmanageengine_opmanagerMatch11.0
OR
zohocorpmanageengine_opmanagerMatch11.1
OR
zohocorpmanageengine_opmanagerMatch11.2
OR
zohocorpmanageengine_opmanagerMatch11.3
OR
zohocorpmanageengine_opmanagerMatch11.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.938 High

EPSS

Percentile

99.1%