CVE-2021-44652

Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
zohocorpmanageengine_o365_manager_plus
𝑥
< 4.4
zohocorpmanageengine_o365_manager_plus
4.4
zohocorpmanageengine_o365_manager_plus
4.4:build4400
zohocorpmanageengine_o365_manager_plus
4.4:build4401
zohocorpmanageengine_o365_manager_plus
4.4:build4402
zohocorpmanageengine_o365_manager_plus
4.4:build4403
zohocorpmanageengine_o365_manager_plus
4.4:build4406
zohocorpmanageengine_o365_manager_plus
4.4:build4407
zohocorpmanageengine_o365_manager_plus
4.4:build4408
zohocorpmanageengine_o365_manager_plus
4.4:build4410
zohocorpmanageengine_o365_manager_plus
4.4:build4411
zohocorpmanageengine_o365_manager_plus
4.4:build4412
zohocorpmanageengine_o365_manager_plus
4.4:build4413
zohocorpmanageengine_o365_manager_plus
4.4:build4414
zohocorpmanageengine_o365_manager_plus
4.4:build4415
𝑥
= Vulnerable software versions