CVE Vulnerabilities

CVE-2023-48646

Published: Nov 22, 2023 | Modified: Dec 01, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.

Affected Software

Name Vendor Start Version End Version
Manageengine_recoverymanager_plus Zohocorp * 6.0 (excluding)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6001 (including) 6.0-build6001 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6003 (including) 6.0-build6003 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6005 (including) 6.0-build6005 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6011 (including) 6.0-build6011 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6016 (including) 6.0-build6016 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6017 (including) 6.0-build6017 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6020 (including) 6.0-build6020 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6025 (including) 6.0-build6025 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6026 (including) 6.0-build6026 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6030 (including) 6.0-build6030 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6031 (including) 6.0-build6031 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6032 (including) 6.0-build6032 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6041 (including) 6.0-build6041 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6042 (including) 6.0-build6042 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6043 (including) 6.0-build6043 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6044 (including) 6.0-build6044 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6047 (including) 6.0-build6047 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6049 (including) 6.0-build6049 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6050 (including) 6.0-build6050 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6051 (including) 6.0-build6051 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6053 (including) 6.0-build6053 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6054 (including) 6.0-build6054 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6056 (including) 6.0-build6056 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6057 (including) 6.0-build6057 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6058 (including) 6.0-build6058 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6060 (including) 6.0-build6060 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6061 (including) 6.0-build6061 (including)
Manageengine_recoverymanager_plus Zohocorp 6.0-build6062 (including) 6.0-build6062 (including)

References