PT-2015-3934 · Zoho · Opmanager+2
Published
2015-04-29
·
Updated
2020-02-13
·
CVE-2014-7863
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ManageEngine Applications Manager versions prior to 11.9 build 11912
OpManager versions 8 through 11.5 build 11400
IT360 versions 10.5 and earlier
Description
The issue allows remote attackers and remote authenticated users to read arbitrary files or obtain sensitive information. This can be achieved via the
fileName parameter in a copyfile operation or through a directory listing in a listdirectory operation to the servlet/FailOverHelperServlet.Recommendations
For ManageEngine Applications Manager versions prior to 11.9 build 11912, update to version 11.9 build 11912 or later.
For OpManager versions 8 through 11.5 build 11400, update to a version later than 11.5 build 11400.
For IT360 versions 10.5 and earlier, update to a version later than 10.5.
As a temporary workaround, consider restricting access to the FailOverHelperServlet to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
It360
Zoho Manageengine Applications Manager
Opmanager