VulnerabilityModified
CVE-2021-37922
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
MEDIUM 5.3EPSS 2.30%
Does this matter?
Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.
Description
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- zohocorp/manageengine admanager plus
- Source
- cve@mitre.org
References
- https://www.manageengine.comProduct
- https://www.manageengine.com/products/ad-manager/release-notes.html#7111Release Notes, Vendor Advisory
- https://www.manageengine.comProduct
- https://www.manageengine.com/products/ad-manager/release-notes.html#7111Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.