CVE-2017-11740: Input Validation
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the remote system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-11740?
CVE-2017-11740 is a vulnerability in Zoho ManageEngine Application Manager 13.1 Build 13100 that allows an attacker to upload and execute malicious scripts on the remote system.
How severe is CVE-2017-11740?
CVE-2017-11740 has a severity rating of 8.8, which is considered high.
How does CVE-2017-11740 affect Zoho ManageEngine Application Manager?
CVE-2017-11740 affects Zoho ManageEngine Application Manager 13.1 Build 13100, allowing an attacker to upload and execute malicious scripts.
What is the Common Weakness Enumeration (CWE) for CVE-2017-11740?
The Common Weakness Enumeration (CWE) for CVE-2017-11740 is CWE-20.
Is there a fix for CVE-2017-11740?
Yes, it is recommended to update Zoho ManageEngine Application Manager to a version that is not affected by this vulnerability.