PT-2018-11526 · Zoho · Zoho Manageengine Network Configuration Manager+4

M3

·

Publicado

2018-06-29

·

Atualizado

2023-12-07

·

CVE-2018-12997

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Netflow Analyzer versions prior to build 123137 Zoho ManageEngine Network Configuration Manager versions prior to build 123128 Zoho ManageEngine OpManager versions prior to build 123148 Zoho ManageEngine OpUtils versions prior to build 123161 Zoho ManageEngine Firewall Analyzer versions prior to build 123147
Description The issue allows attackers to bypass access controls and read certain files on the web server without logging in. This is achieved by sending a specially crafted request to the server with the operation set to copyfile and including a fileName substring.
Recommendations For Zoho ManageEngine Netflow Analyzer versions prior to build 123137, update to build 123137 or later. For Zoho ManageEngine Network Configuration Manager versions prior to build 123128, update to build 123128 or later. For Zoho ManageEngine OpManager versions prior to build 123148, update to build 123148 or later. For Zoho ManageEngine OpUtils versions prior to build 123161, update to build 123161 or later. For Zoho ManageEngine Firewall Analyzer versions prior to build 123147, update to build 123147 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12997

Produtos afetados

Zoho Manageengine Firewall Analyzer
Zoho Manageengine Netflow Analyzer
Zoho Manageengine Network Configuration Manager
Zoho Manageengine Opmanager
Zoho Manageengine Oputils