First published: Mon Aug 15 2022(Updated: )
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Analytics Plus | =2.9-build2900 | |
Zohocorp Manageengine Analytics Plus | =2.9-build2901 | |
Zohocorp Manageengine Analytics Plus | =2.9-build2902 | |
Zohocorp Manageengine Analytics Plus | =2.9-build2903 | |
Zohocorp Manageengine Analytics Plus | =2.9-build2904 | |
Zohocorp Manageengine Analytics Plus | =2.9-build2905 | |
Zohocorp Manageengine Analytics Plus | =2.9-build2906 | |
Zohocorp Manageengine Analytics Plus | =2.9-build2907 | |
Zohocorp Manageengine Analytics Plus | =3.0-build3000 | |
Zohocorp Manageengine Analytics Plus | =3.0-build3010 | |
Zohocorp Manageengine Analytics Plus | =3.0-build3020 | |
Zohocorp Manageengine Analytics Plus | =3.0-build3030 | |
Zohocorp Manageengine Analytics Plus | =3.0-build3040 | |
Zohocorp Manageengine Analytics Plus | =3.0-build3050 | |
Zohocorp Manageengine Analytics Plus | =3.1-build3100 | |
Zohocorp Manageengine Analytics Plus | =3.1-build3110 | |
Zohocorp Manageengine Analytics Plus | =3.1-build3120 | |
Zohocorp Manageengine Analytics Plus | =3.1-build3130 | |
Zohocorp Manageengine Analytics Plus | =3.1-build3140 | |
Zohocorp Manageengine Analytics Plus | =3.2-build3200 | |
Zohocorp Manageengine Analytics Plus | =3.2-build3250 | |
Zohocorp Manageengine Analytics Plus | =3.3-build3300 | |
Zohocorp Manageengine Analytics Plus | =3.3-build3310 | |
Zohocorp Manageengine Analytics Plus | =3.4-build3400 | |
Zohocorp Manageengine Analytics Plus | =3.4-build3450 | |
Zohocorp Manageengine Analytics Plus | =3.5-build3500 | |
Zohocorp Manageengine Analytics Plus | =3.6-build3600 | |
Zohocorp Manageengine Analytics Plus | =3.7-build3700 | |
Zohocorp Manageengine Analytics Plus | =3.8-build3800 | |
Zohocorp Manageengine Analytics Plus | =3.9-build3900 | |
Zohocorp Manageengine Analytics Plus | =3.9-build3950 | |
Zohocorp Manageengine Analytics Plus | =4.0-build4000 | |
Zohocorp Manageengine Analytics Plus | =4.1-build4100 | |
Zohocorp Manageengine Analytics Plus | =4.1-build4150 | |
Zohocorp Manageengine Analytics Plus | =4.2-build4200 | |
Zohocorp Manageengine Analytics Plus | =4.2-build4250 | |
Zohocorp Manageengine Analytics Plus | =4.2-build4260 | |
Zohocorp Manageengine Analytics Plus | =4.2-build4270 | |
Zohocorp Manageengine Analytics Plus | =4.2-build4280 | |
Zohocorp Manageengine Analytics Plus | =4.3-build4300 | |
Zohocorp Manageengine Analytics Plus | =4.3-build4310 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Directory Traversal vulnerability in Zoho ManageEngine Analytics Plus is CVE-2020-21642.
The severity of CVE-2020-21642 is critical with a CVSS score of 9.8.
The affected software versions for CVE-2020-21642 are Zoho ManageEngine Analytics Plus 2.9-build2900 to 4.3-build4310.
Remote attackers can exploit CVE-2020-21642 by using a specially crafted request to the ZDBQAREFSUBDIR parameter in the /zropusermgmt API to perform directory traversal and run arbitrary code.
You can find more information about CVE-2020-21642 in the release notes of Zoho ManageEngine Analytics Plus.