
Cloud Vulnerability DB
A community-led vulnerabilities database
Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive, which leads to remote code execution (NVD, CVE).
The vulnerability has been assigned a CVSS v3.1 Base Score of 9.8 CRITICAL with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and allows directory traversal through maliciously crafted ZIP archive entries (NVD).
The vulnerability allows an unauthenticated attacker to achieve remote code execution on the affected system by exploiting the directory traversal capability. This gives the attacker full control over the system with high impacts on confidentiality, integrity and availability (NVD).
Users should upgrade to a version after 12147 to address this vulnerability. The vendor has released patches and updates to fix the issue (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."