ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
References
Link | Resource |
---|---|
https://manageengine.com | Vendor Advisory |
https://www.manageengine.com/itom/advisory/cve-2022-35404.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2022-07-18 13:15
Updated : 2023-08-08 14:22
NVD link : CVE-2022-35404
Mitre link : CVE-2022-35404
CVE.ORG link : CVE-2022-35404
JSON object : View
Products Affected
zohocorp
- manageengine_netflow_analyzer
- manageengine_network_configuration_manager
- manageengine_firewall_analyzer
- manageengine_opmanager
CWE
CWE-20
Improper Input Validation