Remote code execution in ManageEngine Logs360 and Zoho ManageEngine EventLog Analyzer - #VU11204

 

Remote code execution in ManageEngine Logs360 and Zoho ManageEngine EventLog Analyzer - #VU11204

Published: March 22, 2018 / Updated: December 30, 2019


Vulnerability identifier: #VU11204
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to insufficient validation of user-supplied input. A remote attacker can send a specially configured zip-file, gain access to com.adventnet.sa.agent.UploadHandlerServlet through POST-request and execute arbitrary code with privileges of the EventLog user.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

ManageEngine Logs360
Zoho ManageEngine EventLog Analyzer

Remediation

Install update from vendor's website.


External References

Related Security Bulletins