// For flags

CVE-2020-21642

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.

Una vulnerabilidad de Salto de Directorio en el parámetro ZDBQAREFSUBDIR en la API /zropusermgmt en Zoho ManageEngine Analytics Plus versiones anteriores a 4350, permite a atacantes remotos ejecutar código arbitrario.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-08-13 CVE Reserved
  • 2022-08-15 CVE Published
  • 2024-07-30 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2900
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2901
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2902
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2903
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2904
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2905
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2906
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
2.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "2.9"
build2907
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.0
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.0"
build3000
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.0
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.0"
build3010
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.0
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.0"
build3020
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.0
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.0"
build3030
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.0
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.0"
build3040
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.0
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.0"
build3050
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.1
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.1"
build3100
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.1
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.1"
build3110
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.1
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.1"
build3120
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.1
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.1"
build3130
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.1
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.1"
build3140
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.2
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.2"
build3200
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.2
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.2"
build3250
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.3
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.3"
build3300
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.3
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.3"
build3310
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.4
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.4"
build3400
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.4
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.4"
build3450
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.5
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.5"
build3500
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.6
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.6"
build3600
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.7
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.7"
build3700
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.8
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.8"
build3800
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.9"
build3900
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
3.9
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "3.9"
build3950
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.0
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.0"
build4000
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.1
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.1"
build4100
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.1
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.1"
build4150
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.2
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.2"
build4200
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.2
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.2"
build4250
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.2
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.2"
build4260
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.2
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.2"
build4270
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.2
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.2"
build4280
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.3
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.3"
build4300
Affected
Zohocorp
Search vendor "Zohocorp"
Manageengine Analytics Plus
Search vendor "Zohocorp" for product "Manageengine Analytics Plus"
4.3
Search vendor "Zohocorp" for product "Manageengine Analytics Plus" and version "4.3"
build4310
Affected