PT-2015-3934 · Zoho · Opmanager+2

Published

2015-04-29

·

Updated

2020-02-13

·

CVE-2014-7863

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine Applications Manager versions prior to 11.9 build 11912 OpManager versions 8 through 11.5 build 11400 IT360 versions 10.5 and earlier
Description The issue allows remote attackers and remote authenticated users to read arbitrary files or obtain sensitive information. This can be achieved via the fileName parameter in a copyfile operation or through a directory listing in a listdirectory operation to the servlet/FailOverHelperServlet.
Recommendations For ManageEngine Applications Manager versions prior to 11.9 build 11912, update to version 11.9 build 11912 or later. For OpManager versions 8 through 11.5 build 11400, update to a version later than 11.5 build 11400. For IT360 versions 10.5 and earlier, update to a version later than 10.5. As a temporary workaround, consider restricting access to the FailOverHelperServlet to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7863
ZDI-15-162

Affected Products

It360
Zoho Manageengine Applications Manager
Opmanager