ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An attacker can leverage this vulnerability to achieve remote code execution by replacing files executed by Log360 on startup.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.tenable.com/security/research/tra-2021-48 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2021-11-01 21:15
Updated : 2022-07-12 17:42
NVD link : CVE-2021-20136
Mitre link : CVE-2021-20136
CVE.ORG link : CVE-2021-20136
JSON object : View
Products Affected
                zohocorp
- manageengine_log360
CWE
                
                    
                        
                        CWE-306
                        
            Missing Authentication for Critical Function
