Lucene search

K
cveMitreCVE-2020-21641
HistoryAug 15, 2022 - 8:15 p.m.

CVE-2020-21641

2022-08-1520:15:08
CWE-611
mitre
web.nvd.nist.gov
22
5
zoho
manageengine
analytics plus
vulnerability
cve-2020-21641
oob-xxe
nvd
security
xml
remote attackers
arbitrary files
folders
internal ports
crafted xml license file

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.008

Percentile

82.3%

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

Affected configurations

Nvd
Node
zohocorpmanageengine_analytics_plusRange<4.3.5
VendorProductVersionCPE
zohocorpmanageengine_analytics_plus*cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*:*

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

High

EPSS

0.008

Percentile

82.3%

Related for CVE-2020-21641