Absolute Path Traversal Vulnerabilities in ZOHO ManageEngine Products
CVE-2014-5445

Currently unrated

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
4 December 2014

What is CVE-2014-5445?

Multiple absolute path traversal vulnerabilities exist within ZOHO ManageEngine products, specifically in the Netflow Analyzer and IT360 applications. These vulnerabilities enable remote attackers, or authenticated users, to exploit the 'schFilePath' parameter in the CSVServlet and CReportPDFServlet servlets, potentially granting them unauthorized access to sensitive files. This flaw could lead to disclosure of critical information stored on the server, highlighting the importance of prompt remediation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

90% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.