CVE-2014-9372: Path Traversal
Published Dec 16, 2014
·Updated
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
Affected Software
1 affected component
ManageEngine Password Manager Pro<=7.1
Event History
Dec 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9372?
CVE-2014-9372 has a medium severity level due to its ability to permit unauthorized file deletion.
2
How do I fix CVE-2014-9372?
To fix CVE-2014-9372, upgrade ManageEngine Password Manager Pro to version 7103 or later.
3
What kind of attack does CVE-2014-9372 enable?
CVE-2014-9372 enables directory traversal attacks allowing remote attackers to delete arbitrary files.
4
Which versions of ManageEngine Password Manager Pro are affected by CVE-2014-9372?
Versions of ManageEngine Password Manager Pro prior to 7103 are affected by CVE-2014-9372.
5
Is CVE-2014-9372 a remote vulnerability?
Yes, CVE-2014-9372 is classified as a remote vulnerability, allowing attackers to exploit it over the network.