Check Point Reference: | CPAI-2014-1852 |
Date Published: | 22 Oct 2014 |
Severity: | Critical |
Last Updated: | Wednesday 22 October, 2014 |
Source: | |
Industry Reference: | CVE-2014-6037 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | ManageEngine EventLog Analyzer 9.9 build 9002 and prior |
Vulnerability Description | A code execution vulnerability has been reported in ManageEngine EventLog Analyzer. The vulnerability is due to lack of authentication and insufficient input validation in agentUpload when processing zip files. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted zip file to the vulnerable server. |
SmartView Tracker will log the following entries:
Attack Name: Web Server Enforcement Violation.
Attack Information: ManageEngine EventLog Analyzer agentUpload Directory Traversal