PT-2014-7017 · Zoho · It360+2
Published
2014-12-04
·
Updated
2019-07-15
·
CVE-2014-6036
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZOHO ManageEngine OpManager versions 11.3 and earlier
Social IT Plus version 11.0
IT360 versions 10.3, 10.4, and earlier
Description
The issue allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the
fileName parameter. This is related to a directory traversal vulnerability in the multipartRequest servlet.Recommendations
For ZOHO ManageEngine OpManager versions 11.3 and earlier, update to a version later than 11.3 to resolve the issue.
For Social IT Plus version 11.0, update to a version later than 11.0 to resolve the issue.
For IT360 versions 10.3, 10.4, and earlier, update to a version later than 10.4 to resolve the issue.
As a temporary workaround, consider restricting access to the multipartRequest servlet to minimize the risk of exploitation.
Avoid using the
fileName parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
It360
Social It Plus
Zoho Manageengine Opmanager