CVE Vulnerabilities

CVE-2021-44650

Published: Jan 12, 2022 | Modified: Jan 24, 2022
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

Affected Software

Name Vendor Start Version End Version
Manageengine_m365_manager_plus Zohocorp * 4.4 (excluding)
Manageengine_m365_manager_plus Zohocorp 4.4 (including) 4.4 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4400 (including) 4.4-build4400 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4401 (including) 4.4-build4401 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4402 (including) 4.4-build4402 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4403 (including) 4.4-build4403 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4406 (including) 4.4-build4406 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4407 (including) 4.4-build4407 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4408 (including) 4.4-build4408 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4410 (including) 4.4-build4410 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4411 (including) 4.4-build4411 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4412 (including) 4.4-build4412 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4413 (including) 4.4-build4413 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4414 (including) 4.4-build4414 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4415 (including) 4.4-build4415 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4416 (including) 4.4-build4416 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4417 (including) 4.4-build4417 (including)
Manageengine_m365_manager_plus Zohocorp 4.4-build4418 (including) 4.4-build4418 (including)

References