CVE-2014-7863

Scores

EPSS

0.889high88.9%
0%20%40%60%80%100%

Percentile: 88.9%

CVSS

7.5high3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Description

The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-200

Exploits

Exploit ID: 43894

Source: exploitdb

URL: https://www.exploit-db.com/exploits/43894

Vulnerable Software (3)

Type: Configuration

Vendor: *

Product: manageengine_applications_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "11.9",      "vulnerable": true    },    {      "cpe...

Source: nvd

Type: Configuration

Vendor: *

Product: manageengine_it360

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "11.9",      "vulnerable": true    },    {      "cpe...

Source: nvd

Type: Configuration

Vendor: *

Product: manageengine_opmanager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "11.9",      "vulnerable": true    },    {      "cpe...

Source: nvd

End of list