First published: Tue Nov 25 2014(Updated: )
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpUtils | <=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8678 is classified as a medium severity vulnerability.
To mitigate CVE-2014-8678, upgrade to a version of ManageEngine OpUtils later than build 71024.
CVE-2014-8678 allows remote attackers to disclose sensitive files by exploiting the ConfigSaveServlet servlet.
CVE-2014-8678 affects ManageEngine OpUtils versions prior to build 71024.
Yes, CVE-2014-8678 is a file disclosure vulnerability related to crafted filenames.