Vulnerability Description
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Firewall Analyzer | 7.2 |
Related Weaknesses (CWE)
References
- https://www.manageengine.com/products/firewall/release-notes.htmlRelease NotesVendor Advisory
- https://www.manageengine.com/products/firewall/release-notes.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2019-11677?
CVE-2019-11677 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
How severe is CVE-2019-11677?
CVE-2019-11677 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-11677?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Firewall Analyzer.