CVE-2021-28959
Zoho ManageEngine EventLog Analyzer vulnerability analysis and mitigation

Overview

Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive, which leads to remote code execution (NVD, CVE).

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 9.8 CRITICAL with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and allows directory traversal through maliciously crafted ZIP archive entries (NVD).

Impact

The vulnerability allows an unauthenticated attacker to achieve remote code execution on the affected system by exploiting the directory traversal capability. This gives the attacker full control over the system with high impacts on confidentiality, integrity and availability (NVD).

Mitigation and workarounds

Users should upgrade to a version after 12147 to address this vulnerability. The vendor has released patches and updates to fix the issue (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related Zoho ManageEngine EventLog Analyzer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-44228CRITICAL10
  • IBM Db2 logoIBM Db2
  • jansi-debugsource
YesYesDec 10, 2021
CVE-2021-28959CRITICAL9.8
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer
NoYesApr 30, 2021
CVE-2023-35785HIGH8.1
  • Zoho ManageEngine EventLog Analyzer logoZoho ManageEngine EventLog Analyzer
  • cpe:2.3:a:zohocorp:manageengine_adaudit_plus
NoYesAug 28, 2023
CVE-2021-44832MEDIUM6.6
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:apache:log4j
NoYesDec 28, 2021
CVE-2021-45105MEDIUM5.9
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function
NoYesDec 18, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management