PT-2014-7015 · Manageengine · Social It Plus+2
Publicado
2014-12-04
·
Atualizado
2015-04-15
·
CVE-2014-6034
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ManageEngine OpManager versions 8.8 through 11.3
Social IT Plus version 11.0
IT360 versions 10.4 and earlier
Description
The issue allows remote attackers or remote authenticated users to write to and execute arbitrary WAR files. This is achieved by exploiting a directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet. The vulnerability can be triggered via a .. (dot dot) in the
regionID parameter.Recommendations
For ManageEngine OpManager versions 8.8 through 11.3, restrict access to the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet to minimize the risk of exploitation.
For Social IT Plus version 11.0, avoid using the
regionID parameter in the affected API endpoint until the issue is resolved.
For IT360 versions 10.4 and earlier, consider disabling the FileCollector servlet until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
It360
Manageengine Opmanager
Social It Plus