CVE Vulnerabilities

CVE-2021-44652

Published: Jan 12, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_o365_manager_plusZohocorp*4.4 (excluding)
Manageengine_o365_manager_plusZohocorp4.4 (including)4.4 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4400 (including)4.4-build4400 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4401 (including)4.4-build4401 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4402 (including)4.4-build4402 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4403 (including)4.4-build4403 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4406 (including)4.4-build4406 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4407 (including)4.4-build4407 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4408 (including)4.4-build4408 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4410 (including)4.4-build4410 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4411 (including)4.4-build4411 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4412 (including)4.4-build4412 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4413 (including)4.4-build4413 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4414 (including)4.4-build4414 (including)
Manageengine_o365_manager_plusZohocorp4.4-build4415 (including)4.4-build4415 (including)

References