ZohoCorp ManageEngine NetFlow Analyzer 7.0.0.2 Professional Edition

CPE Details

ZohoCorp ManageEngine NetFlow Analyzer 7.0.0.2 Professional Edition
7.0.0.2
2019-05-29
12h42 +00:00
2019-05-29
12h42 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:7.0.0.2:*:*:*:professional:*:*:*

Informations

Vendor

zohocorp

Product

manageengine_netflow_analyzer

Version

7.0.0.2

Software Edition

professional

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-47211 2024-01-08 14h45 +00:00 A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
9.1
Critical
CVE-2023-6105 2023-11-15 20h57 +00:00 An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
5.5
Medium
CVE-2022-35404 2022-07-18 10h25 +00:00 ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
8.2
High
CVE-2019-8929 2019-05-17 12h11 +00:00 An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.
6.1
Medium
CVE-2019-8928 2019-05-17 12h08 +00:00 An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.
6.1
Medium
CVE-2019-8927 2019-05-17 12h05 +00:00 An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup, rep_schedule, rep_Type, schDesc, schName, schSource, selectDeviceDone, task, val10, and val11.
6.1
Medium
CVE-2019-8926 2019-05-17 11h57 +00:00 An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.
6.1
Medium
CVE-2019-8925 2019-05-16 23h15 +00:00 An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via any file name, such as a schFilePath=C:\boot.ini value.
4.3
Medium
CVE-2019-7427 2019-05-07 16h31 +00:00 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
6.1
Medium
CVE-2019-7426 2019-05-07 16h27 +00:00 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
6.1
Medium
CVE-2019-7425 2019-03-17 19h10 +00:00 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.
6.1
Medium
CVE-2019-7424 2019-03-17 19h06 +00:00 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.
6.1
Medium
CVE-2019-7423 2019-03-17 19h02 +00:00 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
6.1
Medium
CVE-2019-7422 2019-03-17 19h00 +00:00 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.
6.1
Medium