Lucene search

K
nvd[email protected]NVD:CVE-2018-12997
HistoryJun 29, 2018 - 12:29 p.m.

CVE-2018-12997

2018-06-2912:29:00
CWE-200
web.nvd.nist.gov
4

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.01

Percentile

84.0%

Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server without login by sending a specially crafted request to the server with the operation=copyfile&fileName= substring.

Affected configurations

Nvd
Node
zohocorpfirewall_analyzerMatch-
OR
zohocorpmanageengine_netflow_analyzerMatch-
OR
zohocorpmanageengine_network_configuration_managerMatch-
OR
zohocorpmanageengine_opmanagerMatch-
OR
zohocorpmanageengine_oputilsMatch-
VendorProductVersionCPE
zohocorpfirewall_analyzer-cpe:2.3:a:zohocorp:firewall_analyzer:-:*:*:*:*:*:*:*
zohocorpmanageengine_netflow_analyzer-cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:-:*:*:*:*:*:*:*
zohocorpmanageengine_network_configuration_manager-cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:-:*:*:*:*:*:*:*
zohocorpmanageengine_opmanager-cpe:2.3:a:zohocorp:manageengine_opmanager:-:*:*:*:*:*:*:*
zohocorpmanageengine_oputils-cpe:2.3:a:zohocorp:manageengine_oputils:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.01

Percentile

84.0%

Related for NVD:CVE-2018-12997