CVE-2014-8678: Infoleak
Published Nov 25, 2014
·Updated
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile."
Affected Software
1 affected component
ManageEngine OpUtils<=7.0
Event History
Nov 25, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8678?
CVE-2014-8678 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-8678?
To mitigate CVE-2014-8678, upgrade to a version of ManageEngine OpUtils later than build 71024.
3
What type of attack does CVE-2014-8678 allow?
CVE-2014-8678 allows remote attackers to disclose sensitive files by exploiting the ConfigSaveServlet servlet.
4
Which versions of ManageEngine OpUtils are affected by CVE-2014-8678?
CVE-2014-8678 affects ManageEngine OpUtils versions prior to build 71024.
5
Is CVE-2014-8678 a file disclosure vulnerability?
Yes, CVE-2014-8678 is a file disclosure vulnerability related to crafted filenames.