HTTP: Zoho ManageEngine OpManager Multiple Directory Traversal

This signature detects attempts to exploit a known vulnerability against Zoho ManageEngine OpManager. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

Affected Products

Zohocorp manageengine_opmanager

Short Name
HTTP:DIR:ZOHO-MEOMGR-MUL-DIRTRV
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-12116 CVE-2020-13818 Directory ManageEngine Multiple OpManager Traversal Zoho
Release Date
06/25/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Zohocorp

CVSS Score

5.0

Found a potential security threat?