CVE-2014-5445: Path Traversal
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5445?
CVE-2014-5445 is considered a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2014-5445?
To fix CVE-2014-5445, upgrade to the latest versions of ZOHO ManageEngine NetFlow Analyzer or IT360 that address these vulnerabilities.
Who is impacted by CVE-2014-5445?
CVE-2014-5445 impacts users of ZOHO ManageEngine NetFlow Analyzer versions 8.6 to 10.2 and IT360 version 10.3.
What types of attacks are possible with CVE-2014-5445?
CVE-2014-5445 allows attackers to exploit absolute path traversal vulnerabilities to read arbitrary files on the server.
Is CVE-2014-5445 a remote exploitation vulnerability?
Yes, CVE-2014-5445 allows both remote attackers and remote authenticated users to exploit the vulnerability.