| Check Point Reference: | CPAI-2021-2404 |
| Date Published: | 28 Sep 2025 |
| Severity: | Critical |
| Last Updated: | Sunday 28 September, 2025 |
| Source: | |
| Industry Reference: | CVE-2021-20078 |
| Protection Provided by: |
Security Gateway |
| Who is Vulnerable? | ZohoCorp ManageEngine OpManager prior to 12.5 ZohoCorp ManageEngine OpManager 12.5 build125000 ZohoCorp ManageEngine OpManager 12.5 build125002 ZohoCorp ManageEngine OpManager 12.5 build125100 ZohoCorp ManageEngine OpManager 12.5 build125101 ZohoCorp ManageEngine OpManager 12.5 build125102 ZohoCorp ManageEngine OpManager 12.5 build125108 ZohoCorp ManageEngine OpManager 12.5 build125110 ZohoCorp ManageEngine OpManager 12.5 build125111 ZohoCorp ManageEngine OpManager 12.5 build125112 ZohoCorp ManageEngine OpManager 12.5 build125113 ZohoCorp ManageEngine OpManager 12.5 build125114 ZohoCorp ManageEngine OpManager 12.5 build125116 ZohoCorp ManageEngine OpManager 12.5 build125117 ZohoCorp ManageEngine OpManager 12.5 build125118 ZohoCorp ManageEngine OpManager 12.5 build125120 ZohoCorp ManageEngine OpManager 12.5 build125121 ZohoCorp ManageEngine OpManager 12.5 build125123 ZohoCorp ManageEngine OpManager 12.5 build125124 ZohoCorp ManageEngine OpManager 12.5 build125125 ZohoCorp ManageEngine OpManager 12.5 build125136 ZohoCorp ManageEngine OpManager 12.5 build125137 ZohoCorp ManageEngine OpManager 12.5 build125139 ZohoCorp ManageEngine OpManager 12.5 build125140 ZohoCorp ManageEngine OpManager 12.5 build125143 ZohoCorp ManageEngine OpManager 12.5 build125144 ZohoCorp ManageEngine OpManager 12.5 build125145 ZohoCorp ManageEngine OpManager 12.5 build125156 ZohoCorp ManageEngine OpManager 12.5 build125157 ZohoCorp ManageEngine OpManager 12.5 build125158 ZohoCorp ManageEngine OpManager 12.5 build125159 ZohoCorp ManageEngine OpManager 12.5 build125161 ZohoCorp ManageEngine OpManager 12.5 build125163 ZohoCorp ManageEngine OpManager 12.5 build125174 ZohoCorp ManageEngine OpManager 12.5 build125175 ZohoCorp ManageEngine OpManager 12.5 build125176 ZohoCorp ManageEngine OpManager 12.5 build125177 ZohoCorp ManageEngine OpManager 12.5 build125178 ZohoCorp ManageEngine OpManager 12.5 build125180 ZohoCorp ManageEngine OpManager 12.5 build125181 ZohoCorp ManageEngine OpManager 12.5 build125192 ZohoCorp ManageEngine OpManager 12.5 build125193 ZohoCorp ManageEngine OpManager 12.5 build125194 ZohoCorp ManageEngine OpManager 12.5 build125195 ZohoCorp ManageEngine OpManager 12.5 build125196 ZohoCorp ManageEngine OpManager 12.5 build125197 ZohoCorp ManageEngine OpManager 12.5 build125198 ZohoCorp ManageEngine OpManager 12.5 build125201 ZohoCorp ManageEngine OpManager 12.5 build125204 ZohoCorp ManageEngine OpManager 12.5 build125212 ZohoCorp ManageEngine OpManager 12.5 build125213 ZohoCorp ManageEngine OpManager 12.5 build125214 ZohoCorp ManageEngine OpManager 12.5 build125215 ZohoCorp ManageEngine OpManager 12.5 build125216 ZohoCorp ManageEngine OpManager 12.5 build125228 ZohoCorp ManageEngine OpManager 12.5 build125229 ZohoCorp ManageEngine OpManager 12.5 build125230 ZohoCorp ManageEngine OpManager 12.5 build125231 ZohoCorp ManageEngine OpManager 12.5 build125232 ZohoCorp ManageEngine OpManager 12.5 build125233 ZohoCorp ManageEngine OpManager 12.5 build125312 |
| Vulnerability Description | A directory traversal vulnerability in ZohoCorp ManageEngine OpManager allows remote attackers to delete any directory or directories on the OS, potentially causing a denial-of-service condition. |
This protection detects attempts to exploit this vulnerability.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Application Servers Protection Violation.
Attack Information: ZohoCorp ManageEngine OpManager Directory Traversal (CVE-2021-20078)