CVE Vulnerabilities

CVE-2024-10839

Improper Restriction of XML External Entity Reference

Published: Nov 08, 2024 | Modified: Nov 13, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_sharepoint_manager_plusZohocorp4.0-4000 (including)4.0-4000 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4001 (including)4.0-4001 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4002 (including)4.0-4002 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4003 (including)4.0-4003 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4004 (including)4.0-4004 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4005 (including)4.0-4005 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4006 (including)4.0-4006 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4007 (including)4.0-4007 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4008 (including)4.0-4008 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4009 (including)4.0-4009 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4010 (including)4.0-4010 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4011 (including)4.0-4011 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4012 (including)4.0-4012 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4013 (including)4.0-4013 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4014 (including)4.0-4014 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4015 (including)4.0-4015 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4016 (including)4.0-4016 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4017 (including)4.0-4017 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4018 (including)4.0-4018 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4019 (including)4.0-4019 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4020 (including)4.0-4020 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4021 (including)4.0-4021 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4022 (including)4.0-4022 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4023 (including)4.0-4023 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4024 (including)4.0-4024 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4025 (including)4.0-4025 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4026 (including)4.0-4026 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4027 (including)4.0-4027 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4028 (including)4.0-4028 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4029 (including)4.0-4029 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4030 (including)4.0-4030 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4031 (including)4.0-4031 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4032 (including)4.0-4032 (including)
Manageengine_sharepoint_manager_plusZohocorp4.0-4033 (including)4.0-4033 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4100 (including)4.1-4100 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4101 (including)4.1-4101 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4102 (including)4.1-4102 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4103 (including)4.1-4103 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4104 (including)4.1-4104 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4105 (including)4.1-4105 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4106 (including)4.1-4106 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4107 (including)4.1-4107 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4108 (including)4.1-4108 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4109 (including)4.1-4109 (including)
Manageengine_sharepoint_manager_plusZohocorp4.1-4110 (including)4.1-4110 (including)
Manageengine_sharepoint_manager_plusZohocorp4.2-4200 (including)4.2-4200 (including)
Manageengine_sharepoint_manager_plusZohocorp4.2-4201 (including)4.2-4201 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4300 (including)4.3-4300 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4301 (including)4.3-4301 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4302 (including)4.3-4302 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4303 (including)4.3-4303 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4304 (including)4.3-4304 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4305 (including)4.3-4305 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4306 (including)4.3-4306 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4307 (including)4.3-4307 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4308 (including)4.3-4308 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4309 (including)4.3-4309 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4310 (including)4.3-4310 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4311 (including)4.3-4311 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4312 (including)4.3-4312 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4313 (including)4.3-4313 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4314 (including)4.3-4314 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4315 (including)4.3-4315 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4316 (including)4.3-4316 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4317 (including)4.3-4317 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4318 (including)4.3-4318 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4319 (including)4.3-4319 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4320 (including)4.3-4320 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4321 (including)4.3-4321 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4322 (including)4.3-4322 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4323 (including)4.3-4323 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4324 (including)4.3-4324 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4325 (including)4.3-4325 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4326 (including)4.3-4326 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4327 (including)4.3-4327 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4328 (including)4.3-4328 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4329 (including)4.3-4329 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4330 (including)4.3-4330 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4331 (including)4.3-4331 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4332 (including)4.3-4332 (including)
Manageengine_sharepoint_manager_plusZohocorp4.3-4333 (including)4.3-4333 (including)
Manageengine_sharepoint_manager_plusZohocorp4.4-4400 (including)4.4-4400 (including)
Manageengine_sharepoint_manager_plusZohocorp4.4-4401 (including)4.4-4401 (including)
Manageengine_sharepoint_manager_plusZohocorp4.4-4402 (including)4.4-4402 (including)
Manageengine_sharepoint_manager_plusZohocorp4.4-4403 (including)4.4-4403 (including)
Manageengine_sharepoint_manager_plusZohocorp4.4-4404 (including)4.4-4404 (including)
Manageengine_sharepoint_manager_plusZohocorp4.5-4500 (including)4.5-4500 (including)
Manageengine_sharepoint_manager_plusZohocorp4.5-4501 (including)4.5-4501 (including)
Manageengine_sharepoint_manager_plusZohocorp4.5-4502 (including)4.5-4502 (including)
Manageengine_sharepoint_manager_plusZohocorp4.5-4503 (including)4.5-4503 (including)

Potential Mitigations

References