CVE-2020-21642

Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
zohocorpmanageengine_analytics_plus
2.9:build2900
zohocorpmanageengine_analytics_plus
2.9:build2901
zohocorpmanageengine_analytics_plus
2.9:build2902
zohocorpmanageengine_analytics_plus
2.9:build2903
zohocorpmanageengine_analytics_plus
2.9:build2904
zohocorpmanageengine_analytics_plus
2.9:build2905
zohocorpmanageengine_analytics_plus
2.9:build2906
zohocorpmanageengine_analytics_plus
2.9:build2907
zohocorpmanageengine_analytics_plus
3.0:build3000
zohocorpmanageengine_analytics_plus
3.0:build3010
zohocorpmanageengine_analytics_plus
3.0:build3020
zohocorpmanageengine_analytics_plus
3.0:build3030
zohocorpmanageengine_analytics_plus
3.0:build3040
zohocorpmanageengine_analytics_plus
3.0:build3050
zohocorpmanageengine_analytics_plus
3.1:build3100
zohocorpmanageengine_analytics_plus
3.1:build3110
zohocorpmanageengine_analytics_plus
3.1:build3120
zohocorpmanageengine_analytics_plus
3.1:build3130
zohocorpmanageengine_analytics_plus
3.1:build3140
zohocorpmanageengine_analytics_plus
3.2:build3200
zohocorpmanageengine_analytics_plus
3.2:build3250
zohocorpmanageengine_analytics_plus
3.3:build3300
zohocorpmanageengine_analytics_plus
3.3:build3310
zohocorpmanageengine_analytics_plus
3.4:build3400
zohocorpmanageengine_analytics_plus
3.4:build3450
zohocorpmanageengine_analytics_plus
3.5:build3500
zohocorpmanageengine_analytics_plus
3.6:build3600
zohocorpmanageengine_analytics_plus
3.7:build3700
zohocorpmanageengine_analytics_plus
3.8:build3800
zohocorpmanageengine_analytics_plus
3.9:build3900
zohocorpmanageengine_analytics_plus
3.9:build3950
zohocorpmanageengine_analytics_plus
4.0:build4000
zohocorpmanageengine_analytics_plus
4.1:build4100
zohocorpmanageengine_analytics_plus
4.1:build4150
zohocorpmanageengine_analytics_plus
4.2:build4200
zohocorpmanageengine_analytics_plus
4.2:build4250
zohocorpmanageengine_analytics_plus
4.2:build4260
zohocorpmanageengine_analytics_plus
4.2:build4270
zohocorpmanageengine_analytics_plus
4.2:build4280
zohocorpmanageengine_analytics_plus
4.3:build4300
zohocorpmanageengine_analytics_plus
4.3:build4310
𝑥
= Vulnerable software versions