Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-7863

Опубликовано: 08 фев. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Высокий

Описание

The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*
Версия до 11.9 (включая)
cpe:2.3:a:zohocorp:manageengine_it360:*:*:*:*:*:*:*:*
Версия до 10.5 (включая)
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
Версия от 8 (включая) до 11.5 (включая)

EPSS

Процентиль: 100%
0.88867
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.

EPSS

Процентиль: 100%
0.88867
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200