First published: Sat Apr 04 2020(Updated: )
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine OpManager | <12.4 | |
Zohocorp ManageEngine OpManager | =12.4 | |
Zohocorp ManageEngine OpManager | =12.4-build124000 | |
Zohocorp ManageEngine OpManager | =12.4-build124011 | |
Zohocorp ManageEngine OpManager | =12.4-build124012 | |
Zohocorp ManageEngine OpManager | =12.4-build124013 | |
Zohocorp ManageEngine OpManager | =12.4-build124014 | |
Zohocorp ManageEngine OpManager | =12.4-build124015 | |
Zohocorp ManageEngine OpManager | =12.4-build124016 | |
Zohocorp ManageEngine OpManager | =12.4-build124022 | |
Zohocorp ManageEngine OpManager | =12.4-build124023 | |
Zohocorp ManageEngine OpManager | =12.4-build124024 | |
Zohocorp ManageEngine OpManager | =12.4-build124025 | |
Zohocorp ManageEngine OpManager | =12.4-build124026 | |
Zohocorp ManageEngine OpManager | =12.4-build124027 | |
Zohocorp ManageEngine OpManager | =12.4-build124030 | |
Zohocorp ManageEngine OpManager | =12.4-build124033 | |
Zohocorp ManageEngine OpManager | =12.4-build124037 | |
Zohocorp ManageEngine OpManager | =12.4-build124039 | |
Zohocorp ManageEngine OpManager | =12.4-build124040 | |
Zohocorp ManageEngine OpManager | =12.4-build124041 | |
Zohocorp ManageEngine OpManager | =12.4-build124042 | |
Zohocorp ManageEngine OpManager | =12.4-build124043 | |
Zohocorp ManageEngine OpManager | =12.4-build124051 | |
Zohocorp ManageEngine OpManager | =12.4-build124053 | |
Zohocorp ManageEngine OpManager | =12.4-build124054 | |
Zohocorp ManageEngine OpManager | =12.4-build124056 | |
Zohocorp ManageEngine OpManager | =12.4-build124058 | |
Zohocorp ManageEngine OpManager | =12.4-build124065 | |
Zohocorp ManageEngine OpManager | =12.4-build124066 | |
Zohocorp ManageEngine OpManager | =12.4-build124067 | |
Zohocorp ManageEngine OpManager | =12.4-build124069 | |
Zohocorp ManageEngine OpManager | =12.4-build124070 | |
Zohocorp ManageEngine OpManager | =12.4-build124071 | |
Zohocorp ManageEngine OpManager | =12.4-build124074 | |
Zohocorp ManageEngine OpManager | =12.4-build124075 | |
Zohocorp ManageEngine OpManager | =12.4-build124081 | |
Zohocorp ManageEngine OpManager | =12.4-build124082 | |
Zohocorp ManageEngine OpManager | =12.4-build124085 | |
Zohocorp ManageEngine OpManager | =12.4-build124086 | |
Zohocorp ManageEngine OpManager | =12.4-build124087 | |
Zohocorp ManageEngine OpManager | =12.4-build124089 | |
Zohocorp ManageEngine OpManager | =12.4-build124095 | |
Zohocorp ManageEngine OpManager | =12.4-build124096 | |
Zohocorp ManageEngine OpManager | =12.4-build124097 | |
Zohocorp ManageEngine OpManager | =12.4-build124098 | |
Zohocorp ManageEngine OpManager | =12.4-build124099 | |
Zohocorp ManageEngine OpManager | =12.4-build124100 | |
Zohocorp ManageEngine OpManager | =12.4-build124101 | |
Zohocorp ManageEngine OpManager | =12.4-build124102 | |
Zohocorp ManageEngine OpManager | =12.4-build124168 | |
Zohocorp ManageEngine OpManager | =12.4-build124169 | |
Zohocorp ManageEngine OpManager | =12.4-build124175 | |
Zohocorp ManageEngine OpManager | =12.4-build124176 | |
Zohocorp ManageEngine OpManager | =12.4-build124178 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
The severity of CVE-2020-11527 in Zoho ManageEngine OpManager before 12.4.181 is high with a CVSS score of 7.5.
Yes, an unauthenticated remote attacker can exploit CVE-2020-11527 in Zoho ManageEngine OpManager before 12.4.181 by sending a specially crafted URI.
To fix CVE-2020-11527 vulnerability in Zoho ManageEngine OpManager before 12.4.181, update to version 12.4.181 or apply the necessary patches provided by the vendor.