7.5
CVSSv3

CVE-2020-12116

Published: 07/05/2020 Updated: 21/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Zoho ManageEngine OpManager Stable build prior to 124196 and Released build prior to 125125 allows an unauthenticated malicious user to read arbitrary files on the server by sending a crafted request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine opmanager

zohocorp manageengine opmanager 12.4

zohocorp manageengine opmanager 12.5

Github Repositories

Proof of concept code to exploit CVE-2020-12116: Unauthenticated arbitrary file read on ManageEngine OpManger.

CVE-2020-12116 Proof of concept code to exploit CVE-2020-12116: Unauthenticated arbitrary file read on ManageEngine OpManger Summary The latest release of OpManger contains a directory traversal vulnerability that allows unrestricted access to every file in the OpManager application This includes private SSH keys, password protected Java keystores, and configuration files con