CVE-2015-8249: Malicious File Upload
Published Sep 27, 2017
·Updated
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
Affected Software
1 affected component
ManageEngine Desktop Central=9.0
Remediation
Event History
Sep 27, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8249?
CVE-2015-8249 is considered a high severity vulnerability due to the risk of remote code execution.
2
How do I fix CVE-2015-8249?
To mitigate CVE-2015-8249, upgrade ManageEngine Desktop Central to version 9.0 build 91093 or later.
3
Who is affected by CVE-2015-8249?
CVE-2015-8249 impacts all installations of ManageEngine Desktop Central version 9.0 prior to build 91093.
4
What can attackers do with CVE-2015-8249?
Attackers can exploit CVE-2015-8249 to upload and execute arbitrary files on the affected server.
5
When was CVE-2015-8249 published?
CVE-2015-8249 was published on December 14, 2015.