Impact
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 contain an authorization bypass that allows attackers to perform path traversal. This weakness permits reading or writing files outside the intended directory structure, potentially exposing sensitive configuration files or other confidential data. The primary consequence is unauthorized access to files, which can lead to information disclosure, configuration tampering or other integrity violations.
Affected Systems
The vulnerability affects ManageEngine OpManager and ManageEngine Network Configuration Manager from ZohoCorp. All releases prior to version 12.8.671 are impacted. Users of these products should verify their installed version and upgrade when possible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity risk. EPSS is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA KEV. Based on the description, the attack vector is inferred to be feasible through the web interface or API without authentication, making it a potential remote exploitation path.
OpenCVE Enrichment