First published: Tue Jun 09 2015(Updated: )
Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or remove accounts by leveraging the guest role.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine NetFlow Analyzer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2959 is rated as a high severity vulnerability due to its potential to allow unauthorized access to sensitive information.
To fix CVE-2015-2959, upgrade to the latest version of Zoho NetFlow Analyzer that includes proper administrative authorization checks.
With CVE-2015-2959, attackers can gain unauthorized access to sensitive information, modify account passwords, or remove user accounts.
CVE-2015-2959 affects versions of Zoho NetFlow Analyzer build 10250 and earlier.
Organizations using vulnerable versions of Zoho NetFlow Analyzer may be at risk from exploitation by remote attackers.