Lucene search

K
cveMitreCVE-2014-8678
HistoryNov 25, 2014 - 3:59 p.m.

CVE-2014-8678

2014-11-2515:59:07
CWE-200
mitre
web.nvd.nist.gov
24
cve-2014-8678
configsaveservlet
manageengine oputils
build 71024
remote attackers
disclose files
crafted filename
savefile
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.365

Percentile

97.2%

The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to “disclose” files via a crafted filename, related to “saveFile.”

Affected configurations

Nvd
Node
manageengineoputilsRange7.0
VendorProductVersionCPE
manageengineoputils*cpe:2.3:a:manageengine:oputils:*:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.365

Percentile

97.2%

Related for CVE-2014-8678