First published: Wed Jan 12 2022(Updated: )
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Cloud Security Plus | <4.1 | |
Zohocorp Manageengine Cloud Security Plus | =4.1 | |
Zohocorp Manageengine Cloud Security Plus | =4.1-build4110 | |
Zohocorp Manageengine Cloud Security Plus | =4.1-build4111 | |
Zohocorp Manageengine Cloud Security Plus | =4.1-build4112 | |
Zohocorp Manageengine Cloud Security Plus | =4.1-build4113 | |
Zohocorp Manageengine Cloud Security Plus | =4.1-build4115 | |
Zohocorp Manageengine Cloud Security Plus | =4.1-build4116 | |
Zohocorp Log360 | <=5.2.2 | |
Zohocorp Manageengine Cloud Security Plus | <=4.1.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44651 is a vulnerability in Zoho ManageEngine CloudSecurityPlus before Build 4117 that allows remote code execution.
CVE-2021-44651 has a severity rating of 8.8 (high).
The updatePersonalizeSettings component of Zoho ManageEngine CloudSecurityPlus is affected by CVE-2021-44651.
CVE-2021-44651 can be exploited through remote code execution.
Yes, CVE-2021-44651 can be fixed by updating to Build 4117 of Zoho ManageEngine CloudSecurityPlus.