PT-2022-8644 · Zoho · Manageengine Analytics Plus

Published

2022-08-15

·

Updated

2022-08-16

·

CVE-2020-21642

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Analytics Plus versions prior to 4350
Description A Directory Traversal issue exists due to the ZDBQAREFSUBDIR parameter in the "/zropusermgmt" API endpoint. This allows remote attackers to potentially run arbitrary code.
Recommendations For versions prior to 4350, update to version 4350 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/zropusermgmt" API endpoint to minimize the risk of exploitation. Avoid using the ZDBQAREFSUBDIR parameter in the affected API endpoint until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-21642

Affected Products

Manageengine Analytics Plus