Lucene search

K
nvd[email protected]NVD:CVE-2021-42099
HistoryNov 30, 2021 - 7:15 p.m.

CVE-2021-42099

2021-11-3019:15:09
CWE-434
web.nvd.nist.gov
1
zoho
m365 manager plus
file-upload
vulnerability
remote code execution

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.012

Percentile

85.7%

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

Affected configurations

Nvd
Node
zohocorpmanageengine_m365_manager_plusMatch-
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4000
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4001
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4002
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4003
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4004
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4005
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4007
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4008
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4009
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4010
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4011
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4012
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4013
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4014
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4100
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4101
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4102
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4103
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4104
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4105
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4106
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4108
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4109
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4110
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4111
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4112
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4113
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4115
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4116
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4117
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4118
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4119
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4200
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4201
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4202
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4203
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4204
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4205
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4206
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4207
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4208
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4209
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4210
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4211
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4212
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4213
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4214
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4215
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4216
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4217
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4218
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4219
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4220
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4221
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4222
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4300
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4301
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4302
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4303
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4304
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4305
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4306
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4308
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4309
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4310
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4311
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4312
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4316
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4317
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4318
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4319
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4320
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4321
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4322
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4324
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4325
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4327
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4328
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4329
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4330
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4331
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4332
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4333
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4334
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4335
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4336
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4400
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4401
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4402
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4403
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4406
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4407
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4408
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4410
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4411
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4412
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4413
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4414
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4415
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4416
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4417
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4418
OR
zohocorpmanageengine_m365_manager_plusMatchbuild_4419
VendorProductVersionCPE
zohocorpmanageengine_m365_manager_plus-cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:-:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4000cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4000:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4001cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4001:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4002cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4002:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4003cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4003:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4004cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4004:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4005cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4005:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4007cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4007:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4008cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4008:*:*:*:*:*:*:*
zohocorpmanageengine_m365_manager_plusbuild_4009cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4009:*:*:*:*:*:*:*
Rows per page:
1-10 of 1041

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.012

Percentile

85.7%

Related for NVD:CVE-2021-42099