CVE-2020-11527

In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
VendorProductVersion
zohocorpmanageengine_opmanager
𝑥
< 12.4
zohocorpmanageengine_opmanager
12.4
zohocorpmanageengine_opmanager
12.4:build124000
zohocorpmanageengine_opmanager
12.4:build124011
zohocorpmanageengine_opmanager
12.4:build124012
zohocorpmanageengine_opmanager
12.4:build124013
zohocorpmanageengine_opmanager
12.4:build124014
zohocorpmanageengine_opmanager
12.4:build124015
zohocorpmanageengine_opmanager
12.4:build124016
zohocorpmanageengine_opmanager
12.4:build124022
zohocorpmanageengine_opmanager
12.4:build124023
zohocorpmanageengine_opmanager
12.4:build124024
zohocorpmanageengine_opmanager
12.4:build124025
zohocorpmanageengine_opmanager
12.4:build124026
zohocorpmanageengine_opmanager
12.4:build124027
zohocorpmanageengine_opmanager
12.4:build124030
zohocorpmanageengine_opmanager
12.4:build124033
zohocorpmanageengine_opmanager
12.4:build124037
zohocorpmanageengine_opmanager
12.4:build124039
zohocorpmanageengine_opmanager
12.4:build124040
zohocorpmanageengine_opmanager
12.4:build124041
zohocorpmanageengine_opmanager
12.4:build124042
zohocorpmanageengine_opmanager
12.4:build124043
zohocorpmanageengine_opmanager
12.4:build124051
zohocorpmanageengine_opmanager
12.4:build124053
zohocorpmanageengine_opmanager
12.4:build124054
zohocorpmanageengine_opmanager
12.4:build124056
zohocorpmanageengine_opmanager
12.4:build124058
zohocorpmanageengine_opmanager
12.4:build124065
zohocorpmanageengine_opmanager
12.4:build124066
zohocorpmanageengine_opmanager
12.4:build124067
zohocorpmanageengine_opmanager
12.4:build124069
zohocorpmanageengine_opmanager
12.4:build124070
zohocorpmanageengine_opmanager
12.4:build124071
zohocorpmanageengine_opmanager
12.4:build124074
zohocorpmanageengine_opmanager
12.4:build124075
zohocorpmanageengine_opmanager
12.4:build124081
zohocorpmanageengine_opmanager
12.4:build124082
zohocorpmanageengine_opmanager
12.4:build124085
zohocorpmanageengine_opmanager
12.4:build124086
zohocorpmanageengine_opmanager
12.4:build124087
zohocorpmanageengine_opmanager
12.4:build124089
zohocorpmanageengine_opmanager
12.4:build124095
zohocorpmanageengine_opmanager
12.4:build124096
zohocorpmanageengine_opmanager
12.4:build124097
zohocorpmanageengine_opmanager
12.4:build124098
zohocorpmanageengine_opmanager
12.4:build124099
zohocorpmanageengine_opmanager
12.4:build124100
zohocorpmanageengine_opmanager
12.4:build124101
zohocorpmanageengine_opmanager
12.4:build124102
zohocorpmanageengine_opmanager
12.4:build124168
zohocorpmanageengine_opmanager
12.4:build124169
zohocorpmanageengine_opmanager
12.4:build124175
zohocorpmanageengine_opmanager
12.4:build124176
zohocorpmanageengine_opmanager
12.4:build124178
𝑥
= Vulnerable software versions