First published: Mon Jan 08 2024(Updated: )
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Firewall Analyzer | <12.7 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127000 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127101 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127130 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127131 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127187 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127244 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127257 | |
Zohocorp Manageengine Firewall Analyzer | =12.7-build127259 | |
Zohocorp Manageengine Netflow Analyzer | <12.7 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127000 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127003 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127101 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127130 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127131 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127187 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127244 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127255 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127257 | |
Zohocorp Manageengine Netflow Analyzer | =12.7-build127259 | |
Zohocorp Manageengine Network Configuration Manager | <12.7 | |
Zohocorp Manageengine Network Configuration Manager | =12.7-build127000 | |
Zohocorp Manageengine Network Configuration Manager | =12.7-build127102 | |
Zohocorp Manageengine Network Configuration Manager | =12.7-build127105 | |
Zohocorp Manageengine Network Configuration Manager | =12.7-build127132 | |
Zohocorp Manageengine Network Configuration Manager | =12.7-build127243 | |
Zohocorp Manageengine Network Configuration Manager | =12.7-build127257 | |
Zohocorp Manageengine Network Configuration Manager | =12.7-build127259 | |
Zohocorp ManageEngine OpManager | <12.7 | |
Zohocorp ManageEngine OpManager | =12.7-build127000 | |
Zohocorp ManageEngine OpManager | =12.7-build127001 | |
Zohocorp ManageEngine OpManager | =12.7-build127002 | |
Zohocorp ManageEngine OpManager | =12.7-build127003 | |
Zohocorp ManageEngine OpManager | =12.7-build127004 | |
Zohocorp ManageEngine OpManager | =12.7-build127100 | |
Zohocorp ManageEngine OpManager | =12.7-build127101 | |
Zohocorp ManageEngine OpManager | =12.7-build127102 | |
Zohocorp ManageEngine OpManager | =12.7-build127103 | |
Zohocorp ManageEngine OpManager | =12.7-build127104 | |
Zohocorp ManageEngine OpManager | =12.7-build127109 | |
Zohocorp ManageEngine OpManager | =12.7-build127116 | |
Zohocorp ManageEngine OpManager | =12.7-build127117 | |
Zohocorp ManageEngine OpManager | =12.7-build127118 | |
Zohocorp ManageEngine OpManager | =12.7-build127119 | |
Zohocorp ManageEngine OpManager | =12.7-build127120 | |
Zohocorp ManageEngine OpManager | =12.7-build127122 | |
Zohocorp ManageEngine OpManager | =12.7-build127123 | |
Zohocorp ManageEngine OpManager | =12.7-build127131 | |
Zohocorp ManageEngine OpManager | =12.7-build127133 | |
Zohocorp ManageEngine OpManager | =12.7-build127134 | |
Zohocorp ManageEngine OpManager | =12.7-build127136 | |
Zohocorp ManageEngine OpManager | =12.7-build127138 | |
Zohocorp ManageEngine OpManager | =12.7-build127140 | |
Zohocorp ManageEngine OpManager | =12.7-build127141 | |
Zohocorp ManageEngine OpManager | =12.7-build127185 | |
Zohocorp ManageEngine OpManager | =12.7-build127186 | |
Zohocorp ManageEngine OpManager | =12.7-build127187 | |
Zohocorp ManageEngine OpManager | =12.7-build127188 | |
Zohocorp ManageEngine OpManager | =12.7-build127189 | |
Zohocorp ManageEngine OpManager | =12.7-build127191 | |
Zohocorp ManageEngine OpManager | =12.7-build127240 | |
Zohocorp ManageEngine OpManager | =12.7-build127241 | |
Zohocorp ManageEngine OpManager | =12.7-build127242 | |
Zohocorp ManageEngine OpManager | =12.7-build127243 | |
Zohocorp ManageEngine OpManager | =12.7-build127255 | |
Zohocorp ManageEngine OpManager | =12.7-build127256 | |
Zohocorp ManageEngine OpManager | =12.7-build127257 | |
Zohocorp ManageEngine OpManager | =12.7-build127258 | |
Zohocorp ManageEngine OpManager | =12.7-build127259 | |
Zohocorp Manageengine Opmanager Msp | <12.7 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127109 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127122 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127123 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127138 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127139 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127140 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127141 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127142 | |
Zohocorp Manageengine Opmanager Msp | =12.7-build127259 | |
Zohocorp Manageengine Opmanager Plus | <12.7 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127109 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127122 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127123 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127138 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127139 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127140 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127141 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127142 | |
Zohocorp Manageengine Opmanager Plus | =12.7-build127259 | |
Zohocorp Manageengine Oputils | <12.7 | |
Zohocorp Manageengine Oputils | =12.7-build127101 | |
Zohocorp Manageengine Oputils | =12.7-build127117 | |
Zohocorp Manageengine Oputils | =12.7-build127134 | |
Zohocorp Manageengine Oputils | =12.7-build127241 | |
Zohocorp Manageengine Oputils | =12.7-build127242 | |
Zohocorp Manageengine Oputils | =12.7-build127258 | |
Zohocorp Manageengine Oputils | =12.7-build127259 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.