First published: Thu Jun 04 2020(Updated: )
In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager | ||
Zohocorp ManageEngine OpManager | <12.5 | |
Zohocorp ManageEngine OpManager | =12.5 | |
Zohocorp ManageEngine OpManager | =12.5-build125000 | |
Zohocorp ManageEngine OpManager | =12.5-build125002 | |
Zohocorp ManageEngine OpManager | =12.5-build125100 | |
Zohocorp ManageEngine OpManager | =12.5-build125101 | |
Zohocorp ManageEngine OpManager | =12.5-build125102 | |
Zohocorp ManageEngine OpManager | =12.5-build125108 | |
Zohocorp ManageEngine OpManager | =12.5-build125110 | |
Zohocorp ManageEngine OpManager | =12.5-build125111 | |
Zohocorp ManageEngine OpManager | =12.5-build125112 | |
Zohocorp ManageEngine OpManager | =12.5-build125113 | |
Zohocorp ManageEngine OpManager | =12.5-build125114 | |
Zohocorp ManageEngine OpManager | =12.5-build125116 | |
Zohocorp ManageEngine OpManager | =12.5-build125117 | |
Zohocorp ManageEngine OpManager | =12.5-build125118 | |
Zohocorp ManageEngine OpManager | =12.5-build125120 | |
Zohocorp ManageEngine OpManager | =12.5-build125121 | |
Zohocorp ManageEngine OpManager | =12.5-build125123 | |
Zohocorp ManageEngine OpManager | =12.5-build125124 | |
Zohocorp ManageEngine OpManager | =12.5-build125125 | |
Zohocorp ManageEngine OpManager | =12.5-build125136 | |
Zohocorp ManageEngine OpManager | =12.5-build125137 | |
Zohocorp ManageEngine OpManager | =12.5-build125139 | |
Zohocorp ManageEngine OpManager | =12.5-build125140 | |
Zohocorp ManageEngine OpManager | =12.5-build125143 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13818 is a vulnerability in ManageEngine OpManager that allows remote attackers to disclose sensitive information on affected installations.
No, authentication is not required to exploit CVE-2020-13818.
CVE-2020-13818 has a severity rating of 7.5 (High).
ManageEngine OpManager versions up to 12.5 (build 125144) are affected by CVE-2020-13818.
To fix CVE-2020-13818, it is recommended to upgrade to a version of ManageEngine OpManager that is not affected by the vulnerability. Please refer to the official documentation for the latest version and upgrade instructions.