PT-2014-7016 · Zoho · Zoho Manageengine Opmanager

Published

2014-12-04

·

Updated

2015-04-15

·

CVE-2014-6035

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZOHO ManageEngine OpManager versions 11.4 and earlier
Description A directory traversal issue exists in the FileCollector servlet, allowing remote attackers to write and execute arbitrary files. This is achieved by using a .. (dot dot) in the FILENAME parameter.
Recommendations For ZOHO ManageEngine OpManager versions 11.4 and earlier, consider restricting access to the FileCollector servlet until a patch is available. As a temporary workaround, avoid using the FILENAME parameter in the affected API endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-6035
ZDI-15-142

Affected Products

Zoho Manageengine Opmanager