CVE-2019-11677

The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
zohocorpmanageengine_firewall_analyzer
7.2:7020
zohocorpmanageengine_firewall_analyzer
7.2:7021
zohocorpmanageengine_firewall_analyzer
7.4:7400
zohocorpmanageengine_firewall_analyzer
7.6:7600
zohocorpmanageengine_firewall_analyzer
8.0:8000
zohocorpmanageengine_firewall_analyzer
8.1:8110
zohocorpmanageengine_firewall_analyzer
8.3:8300
zohocorpmanageengine_firewall_analyzer
8.5:8500
zohocorpmanageengine_firewall_analyzer
12.0:12000
zohocorpmanageengine_firewall_analyzer
12.2:12200
zohocorpmanageengine_firewall_analyzer
12.3:12300
zohocorpmanageengine_firewall_analyzer
12.3:123008
zohocorpmanageengine_firewall_analyzer
12.3:123027
zohocorpmanageengine_firewall_analyzer
12.3:123045
zohocorpmanageengine_firewall_analyzer
12.3:123057
zohocorpmanageengine_firewall_analyzer
12.3:123064
zohocorpmanageengine_firewall_analyzer
12.3:123070
zohocorpmanageengine_firewall_analyzer
12.3:123083
zohocorpmanageengine_firewall_analyzer
12.3:123092
zohocorpmanageengine_firewall_analyzer
12.3:123126
zohocorpmanageengine_firewall_analyzer
12.3:123129
zohocorpmanageengine_firewall_analyzer
12.3:123137
zohocorpmanageengine_firewall_analyzer
12.3:123151
zohocorpmanageengine_firewall_analyzer
12.3:123156
zohocorpmanageengine_firewall_analyzer
12.3:123164
zohocorpmanageengine_firewall_analyzer
12.3:123169
zohocorpmanageengine_firewall_analyzer
12.3:123177
zohocorpmanageengine_firewall_analyzer
12.3:123182
zohocorpmanageengine_firewall_analyzer
12.3:123185
zohocorpmanageengine_firewall_analyzer
12.3:123186
zohocorpmanageengine_firewall_analyzer
12.3:123194
zohocorpmanageengine_firewall_analyzer
12.3:123197
zohocorpmanageengine_firewall_analyzer
12.3:123208
zohocorpmanageengine_firewall_analyzer
12.3:123218
zohocorpmanageengine_firewall_analyzer
12.3:123222
zohocorpmanageengine_firewall_analyzer
12.3:123223
𝑥
= Vulnerable software versions