CVE-2019-11677: XEE
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11677?
CVE-2019-11677 is a vulnerability in Zoho ManageEngine Firewall Analyzer that allows for XML External Entity (XXE) Injection.
How severe is CVE-2019-11677?
CVE-2019-11677 has a severity rating of 9.8 (Critical).
Which versions of Zoho ManageEngine Firewall Analyzer are affected by CVE-2019-11677?
Versions 7.2-7020 to 12.3-123223 of Zoho ManageEngine Firewall Analyzer are affected by CVE-2019-11677.
How can I fix CVE-2019-11677?
To fix CVE-2019-11677, you should update Zoho ManageEngine Firewall Analyzer to version 12.3 Build 123224 or later.
Where can I find more information about CVE-2019-11677?
You can find more information about CVE-2019-11677 in Zoho ManageEngine Firewall Analyzer's release notes: [https://www.manageengine.com/products/firewall/release-notes.html](https://www.manageengine.com/products/firewall/release-notes.html)