CVE-2022-32551

Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus_msp
𝑥
< 10.6
zohocorpmanageengine_servicedesk_plus_msp
10.6
zohocorpmanageengine_servicedesk_plus_msp
10.6:10600
zohocorpmanageengine_servicedesk_plus_msp
10.6:10601
zohocorpmanageengine_servicedesk_plus_msp
10.6:10602
zohocorpmanageengine_servicedesk_plus_msp
10.6:10603
𝑥
= Vulnerable software versions