CVE-2021-37919: Malicious File Upload
Published Oct 7, 2021
·Updated
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Affected Software
6 affected components
ZohoCorp ManageEngine ADManager Plus<7.1
ZohoCorp ManageEngine ADManager Plus=7.1
ZohoCorp ManageEngine ADManager Plus=7.1-7100
ZohoCorp ManageEngine ADManager Plus=7.1-7101
ZohoCorp ManageEngine ADManager Plus=7.1-7102
ZohoCorp ManageEngine ADManager Plus=7.1-7110
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine ADManager Plusto a version that resolves this vulnerability.Fixed in 7110 and prior
Event History
Oct 7, 2021
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Zoho ManageEngine ADManager Plus?
The vulnerability ID for Zoho ManageEngine ADManager Plus is CVE-2021-37919.
2
What is the severity of CVE-2021-37919?
The severity of CVE-2021-37919 is critical with a severity value of 9.8.
3
What is the affected software version for CVE-2021-37919?
The affected software version for CVE-2021-37919 is Zoho ManageEngine ADManager Plus version 7.1.1.0 and prior.
4
What is the impact of CVE-2021-37919?
CVE-2021-37919 allows unrestricted file upload, which leads to remote code execution.
5
How can I fix CVE-2021-37919?
To fix CVE-2021-37919, update to Zoho ManageEngine ADManager Plus version 7.1.1.1 or later.