Vulnerability Description
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Analytics Plus | < 4.3.5 |
Related Weaknesses (CWE)
References
- https://www.manageengine.com/analytics-plus/release-notes.htmlRelease NotesVendor Advisory
- https://www.manageengine.com/analytics-plus/release-notes.htmlRelease NotesVendor Advisory
FAQ
What is CVE-2020-21641?
CVE-2020-21641 is a vulnerability with a CVSS score of 7.5 (HIGH). Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via ...
How severe is CVE-2020-21641?
CVE-2020-21641 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-21641?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Analytics Plus.