CVE-2021-44652

EUVD-2021-31472
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_o365_manager_plus
𝑥
< 4.4
zohocorpmanageengine_o365_manager_plus
4.4
zohocorpmanageengine_o365_manager_plus
4.4:build4400
zohocorpmanageengine_o365_manager_plus
4.4:build4401
zohocorpmanageengine_o365_manager_plus
4.4:build4402
zohocorpmanageengine_o365_manager_plus
4.4:build4403
zohocorpmanageengine_o365_manager_plus
4.4:build4406
zohocorpmanageengine_o365_manager_plus
4.4:build4407
zohocorpmanageengine_o365_manager_plus
4.4:build4408
zohocorpmanageengine_o365_manager_plus
4.4:build4410
zohocorpmanageengine_o365_manager_plus
4.4:build4411
zohocorpmanageengine_o365_manager_plus
4.4:build4412
zohocorpmanageengine_o365_manager_plus
4.4:build4413
zohocorpmanageengine_o365_manager_plus
4.4:build4414
zohocorpmanageengine_o365_manager_plus
4.4:build4415
𝑥
= Vulnerable software versions