CVE-2015-2959: High severity zoho manageengine netflow analyzer vulnerability
Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2959?
CVE-2015-2959 is rated as a high severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2015-2959?
To fix CVE-2015-2959, upgrade to the latest version of Zoho NetFlow Analyzer that includes proper administrative authorization checks.
What types of attacks are possible with CVE-2015-2959?
With CVE-2015-2959, attackers can gain unauthorized access to sensitive information, modify account passwords, or remove user accounts.
Which versions of Zoho NetFlow Analyzer are affected by CVE-2015-2959?
CVE-2015-2959 affects versions of Zoho NetFlow Analyzer build 10250 and earlier.
Who can be affected by the CVE-2015-2959 vulnerability?
Organizations using vulnerable versions of Zoho NetFlow Analyzer may be at risk from exploitation by remote attackers.