First published: Wed Oct 13 2021(Updated: )
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADManager Plus | <7.1 | |
Zohocorp ManageEngine ADManager Plus | =7.1 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7100 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7101 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7102 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20130 is a post-authentication remote code execution vulnerability in ManageEngine ADManager Plus Build 7111.
CVE-2021-20130 affects ManageEngine ADManager Plus Build 7111 due to improperly validated file uploads in the PasswordExpiry interface.
The severity of CVE-2021-20130 is high with a severity value of 8.8.
To fix the CVE-2021-20130 vulnerability, it is recommended to update ManageEngine ADManager Plus to a version higher than Build 7111.
You can find more information about CVE-2021-20130 at the following reference link: https://www.tenable.com/security/research/tra-2021-43