VulnerabilityModified
CVE-2014-0344
Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.
MEDIUM 6.5EPSS 5.58%
Does this matter?
Lower severity and a low EPSS score (5.58%). Track it; it rarely justifies an emergency change on its own.
Description
Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obtain Admin access by using the name parameter in conjunction with a true value of the edit parameter.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 5.58% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- zohocorp/manageengine opstor
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/140886Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/66499
- http://www.kb.cert.org/vuls/id/140886Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/66499
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.