ManageEngine Security Updates – 09 January 2024

ManageEngine has released security updates to address a critical vulnerability across multiple product builds till 127259.

The addressed vulnerability could allow the remote authenticated attacker to traverse directories by sending a specially crafted URL request containing “dot dot” sequences (/../) to create arbitrary files on the affected systems.

ManageEngine OpManager Directory Traversal Vulnerability (CVE-2023-47211):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information

Affected products:

  • OpManager , OpManager Plus , OpManager MSP.
  • Network Configuration Manager.
  • NetFlow Analyzer.
  • Firewall Analyzer.
  • OpUtils.
Vulnerabilities

CVE-2023-47211

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

ManageEngine Security Advisory

References