VulnerabilityModified
CVE-2020-12116
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
HIGH 7.5EPSS 97.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 97.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 97.42% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- zohocorp/manageengine opmanager
- Source
- cve@mitre.org
References
- https://www.manageengine.com/network-monitoring/help/read-me-complete.htmlVendor Advisory
- https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125125Vendor Advisory
- https://www.manageengine.com/network-monitoring/help/read-me-complete.htmlVendor Advisory
- https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125125Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.