// For flags

CVE-2019-11677

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.

La funciĆ³n de importaciĆ³n de informes personalizados en Zoho ManageEngine Firewall Analyzer versiones anteriores a 12.3 Build 123224 es vulnerable a XML External Entity (XXE) Injection.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-05-02 CVE Reserved
  • 2019-05-02 CVE Published
  • 2023-03-23 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
7.2
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "7.2"
7020
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
7.2
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "7.2"
7021
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
7.4
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "7.4"
7400
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
7.6
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "7.6"
7600
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
8.0
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "8.0"
8000
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
8.1
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "8.1"
8110
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
8.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "8.3"
8300
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
8.5
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "8.5"
8500
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.0
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.0"
12000
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.2
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.2"
12200
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
12300
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123008
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123027
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123045
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123057
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123064
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123070
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123083
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123092
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123126
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123129
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123137
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123151
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123156
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123164
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123169
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123177
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123182
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123185
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123186
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123194
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123197
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123208
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123218
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123222
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Firewall Analyzer
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer"
12.3
Search vendor "Zohocorp" for product "Manageengine Firewall Analyzer" and version "12.3"
123223
Affected