Lucene search

K
nvd[email protected]NVD:CVE-2020-21641
HistoryAug 15, 2022 - 8:15 p.m.

CVE-2020-21641

2022-08-1520:15:08
CWE-611
web.nvd.nist.gov
5
cve-2020-21641
zoho manageengine
oob-xxe
xml external entity
vulnerability
remote attackers
arbitrary files
enumerate folders
scan internal ports
crafted xml license file

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.008

Percentile

82.3%

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.

Affected configurations

Nvd
Node
zohocorpmanageengine_analytics_plusRange<4.3.5
VendorProductVersionCPE
zohocorpmanageengine_analytics_plus*cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.008

Percentile

82.3%

Related for NVD:CVE-2020-21641