SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0344

Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.

MEDIUM 6.5EPSS 5.58%

Does this matter?

Lower severity and a low EPSS score (5.58%). Track it; it rarely justifies an emergency change on its own.

Description

Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
5.58% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
zohocorp/manageengine opstor
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.