← Back

CVE-2023-47211

Published: Jan 8, 2024Modified: Nov 4, 2025

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

Affected (97)

7 products
Manageengine Firewall Analyzer
Manageengine Netflow Analyzer
Manageengine Opmanager
Manageengine Opmanager Msp
Manageengine Opmanager Plus
Manageengine Oputils
Configuration A
97 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 12.7
Version 12.7 build127000
Version 12.7 build127101
Version 12.7 build127130
Version 12.7 build127131
Version 12.7 build127187
Version 12.7 build127244
Version 12.7 build127257
Version 12.7 build127259
Zohocorp
Before 12.7
Version 12.7 build127000
Version 12.7 build127003
Version 12.7 build127101
Version 12.7 build127130
Version 12.7 build127131
Version 12.7 build127187
Version 12.7 build127244
Version 12.7 build127255
Version 12.7 build127257
Version 12.7 build127259
Zohocorp
Before 12.7
Version 12.7 build127000
Version 12.7 build127102
Version 12.7 build127105
Version 12.7 build127132
Version 12.7 build127243
Version 12.7 build127257
Version 12.7 build127259
Zohocorp
Before 12.7
Version 12.7 build127000
Version 12.7 build127001
Version 12.7 build127002
Version 12.7 build127003
Version 12.7 build127004
Version 12.7 build127100
Version 12.7 build127101
Version 12.7 build127102
Version 12.7 build127103
Version 12.7 build127104
Version 12.7 build127109
Version 12.7 build127116
Version 12.7 build127117
Version 12.7 build127118
Version 12.7 build127119
Version 12.7 build127120
Version 12.7 build127122
Version 12.7 build127123
Version 12.7 build127131
Version 12.7 build127133
Version 12.7 build127134
Version 12.7 build127136
Version 12.7 build127138
Version 12.7 build127140
Version 12.7 build127141
Version 12.7 build127185
Version 12.7 build127186
Version 12.7 build127187
Version 12.7 build127188
Version 12.7 build127189
Version 12.7 build127191
Version 12.7 build127240
Version 12.7 build127241
Version 12.7 build127242
Version 12.7 build127243
Version 12.7 build127255
Version 12.7 build127256
Version 12.7 build127257
Version 12.7 build127258
Version 12.7 build127259
Zohocorp
Before 12.7
Version 12.7 build127109
Version 12.7 build127122
Version 12.7 build127123
Version 12.7 build127138
Version 12.7 build127139
Version 12.7 build127140
Version 12.7 build127141
Version 12.7 build127142
Version 12.7 build127259
Zohocorp
Before 12.7
Version 12.7 build127109
Version 12.7 build127122
Version 12.7 build127123
Version 12.7 build127138
Version 12.7 build127139
Version 12.7 build127140
Version 12.7 build127141
Version 12.7 build127142
Version 12.7 build127259
Zohocorp
Before 12.7
Version 12.7 build127101
Version 12.7 build127117
Version 12.7 build127134
Version 12.7 build127241
Version 12.7 build127242
Version 12.7 build127258
Version 12.7 build127259

References (5)

Source: talos-cna@cisco.com
ExploitThird Party Advisory
Source: talos-cna@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.