Lucene search

K
cveTenableCVE-2021-20078
HistoryApr 01, 2021 - 7:15 p.m.

CVE-2021-20078

2021-04-0119:15:13
CWE-22
tenable
web.nvd.nist.gov
50
cve-2021-20078
manage engine opmanager
remote denial of service
path traversal
spark gateway component
vulnerability

CVSS2

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:C/A:C

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.142

Percentile

95.7%

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

Affected configurations

Nvd
Node
zohocorpmanageengine_opmanagerRange<12.5
OR
zohocorpmanageengine_opmanagerMatch12.5build125000
OR
zohocorpmanageengine_opmanagerMatch12.5build125002
OR
zohocorpmanageengine_opmanagerMatch12.5build125100
OR
zohocorpmanageengine_opmanagerMatch12.5build125101
OR
zohocorpmanageengine_opmanagerMatch12.5build125102
OR
zohocorpmanageengine_opmanagerMatch12.5build125108
OR
zohocorpmanageengine_opmanagerMatch12.5build125110
OR
zohocorpmanageengine_opmanagerMatch12.5build125111
OR
zohocorpmanageengine_opmanagerMatch12.5build125112
OR
zohocorpmanageengine_opmanagerMatch12.5build125113
OR
zohocorpmanageengine_opmanagerMatch12.5build125114
OR
zohocorpmanageengine_opmanagerMatch12.5build125116
OR
zohocorpmanageengine_opmanagerMatch12.5build125117
OR
zohocorpmanageengine_opmanagerMatch12.5build125118
OR
zohocorpmanageengine_opmanagerMatch12.5build125120
OR
zohocorpmanageengine_opmanagerMatch12.5build125121
OR
zohocorpmanageengine_opmanagerMatch12.5build125123
OR
zohocorpmanageengine_opmanagerMatch12.5build125124
OR
zohocorpmanageengine_opmanagerMatch12.5build125125
OR
zohocorpmanageengine_opmanagerMatch12.5build125136
OR
zohocorpmanageengine_opmanagerMatch12.5build125137
OR
zohocorpmanageengine_opmanagerMatch12.5build125139
OR
zohocorpmanageengine_opmanagerMatch12.5build125140
OR
zohocorpmanageengine_opmanagerMatch12.5build125143
OR
zohocorpmanageengine_opmanagerMatch12.5build125144
OR
zohocorpmanageengine_opmanagerMatch12.5build125145
OR
zohocorpmanageengine_opmanagerMatch12.5build125156
OR
zohocorpmanageengine_opmanagerMatch12.5build125157
OR
zohocorpmanageengine_opmanagerMatch12.5build125158
OR
zohocorpmanageengine_opmanagerMatch12.5build125159
OR
zohocorpmanageengine_opmanagerMatch12.5build125161
OR
zohocorpmanageengine_opmanagerMatch12.5build125163
OR
zohocorpmanageengine_opmanagerMatch12.5build125174
OR
zohocorpmanageengine_opmanagerMatch12.5build125175
OR
zohocorpmanageengine_opmanagerMatch12.5build125176
OR
zohocorpmanageengine_opmanagerMatch12.5build125177
OR
zohocorpmanageengine_opmanagerMatch12.5build125178
OR
zohocorpmanageengine_opmanagerMatch12.5build125180
OR
zohocorpmanageengine_opmanagerMatch12.5build125181
OR
zohocorpmanageengine_opmanagerMatch12.5build125192
OR
zohocorpmanageengine_opmanagerMatch12.5build125193
OR
zohocorpmanageengine_opmanagerMatch12.5build125194
OR
zohocorpmanageengine_opmanagerMatch12.5build125195
OR
zohocorpmanageengine_opmanagerMatch12.5build125196
OR
zohocorpmanageengine_opmanagerMatch12.5build125197
OR
zohocorpmanageengine_opmanagerMatch12.5build125198
OR
zohocorpmanageengine_opmanagerMatch12.5build125201
OR
zohocorpmanageengine_opmanagerMatch12.5build125204
OR
zohocorpmanageengine_opmanagerMatch12.5build125212
OR
zohocorpmanageengine_opmanagerMatch12.5build125213
OR
zohocorpmanageengine_opmanagerMatch12.5build125214
OR
zohocorpmanageengine_opmanagerMatch12.5build125215
OR
zohocorpmanageengine_opmanagerMatch12.5build125216
OR
zohocorpmanageengine_opmanagerMatch12.5build125228
OR
zohocorpmanageengine_opmanagerMatch12.5build125229
OR
zohocorpmanageengine_opmanagerMatch12.5build125230
OR
zohocorpmanageengine_opmanagerMatch12.5build125231
OR
zohocorpmanageengine_opmanagerMatch12.5build125232
OR
zohocorpmanageengine_opmanagerMatch12.5build125233
OR
zohocorpmanageengine_opmanagerMatch12.5build125312
OR
zohocorpmanageengine_opmanagerMatch12.5build125323
OR
zohocorpmanageengine_opmanagerMatch12.5build125324
OR
zohocorpmanageengine_opmanagerMatch12.5build125326
OR
zohocorpmanageengine_opmanagerMatch12.5build125328
OR
zohocorpmanageengine_opmanagerMatch12.5build125329
OR
zohocorpmanageengine_opmanagerMatch12.5build125340
OR
zohocorpmanageengine_opmanagerMatch12.5build125341
OR
zohocorpmanageengine_opmanagerMatch12.5build125342
OR
zohocorpmanageengine_opmanagerMatch12.5build125343
OR
zohocorpmanageengine_opmanagerMatch12.5build125344
VendorProductVersionCPE
zohocorpmanageengine_opmanager*cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125000:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125002:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125100:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125101:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125102:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125108:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125110:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125111:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125112:*:*:*:*:*:*
Rows per page:
1-10 of 711

CNA Affected

[
  {
    "product": "Manage Engine OpManager",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "All versions prior to version build 125346"
      }
    ]
  }
]

CVSS2

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:C/A:C

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.142

Percentile

95.7%

Related for CVE-2021-20078