First published: Wed Oct 13 2021(Updated: )
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADManager Plus | <7.1 | |
Zohocorp ManageEngine ADManager Plus | =7.1 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7100 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7101 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7102 | |
Zohocorp ManageEngine ADManager Plus | =7.1-7110 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20131 is a vulnerability that allows for remote code execution in ManageEngine ADManager Plus Build 7111.
CVE-2021-20131 has a severity rating of 8.8, which is considered high.
CVE-2021-20131 occurs due to improperly validated file uploads in the Personalization interface of ManageEngine ADManager Plus Build 7111.
ManageEngine ADManager Plus versions 7.1, 7.1-7100, 7.1-7101, 7.1-7102, and 7.1-7110 are affected by CVE-2021-20131.
Patch/update to a fixed version of ManageEngine ADManager Plus, such as version 7111, to fix CVE-2021-20131.