Check Point Advisories

ZohoCorp ManageEngine OpManager Directory Traversal (CVE-2021-20078)

Check Point Reference: CPAI-2021-2404
Date Published: 28 Sep 2025
Severity: Critical
Last Updated: Sunday 28 September, 2025
Source:
Industry Reference:CVE-2021-20078
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? ZohoCorp ManageEngine OpManager prior to 12.5
ZohoCorp ManageEngine OpManager 12.5 build125000
ZohoCorp ManageEngine OpManager 12.5 build125002
ZohoCorp ManageEngine OpManager 12.5 build125100
ZohoCorp ManageEngine OpManager 12.5 build125101
ZohoCorp ManageEngine OpManager 12.5 build125102
ZohoCorp ManageEngine OpManager 12.5 build125108
ZohoCorp ManageEngine OpManager 12.5 build125110
ZohoCorp ManageEngine OpManager 12.5 build125111
ZohoCorp ManageEngine OpManager 12.5 build125112
ZohoCorp ManageEngine OpManager 12.5 build125113
ZohoCorp ManageEngine OpManager 12.5 build125114
ZohoCorp ManageEngine OpManager 12.5 build125116
ZohoCorp ManageEngine OpManager 12.5 build125117
ZohoCorp ManageEngine OpManager 12.5 build125118
ZohoCorp ManageEngine OpManager 12.5 build125120
ZohoCorp ManageEngine OpManager 12.5 build125121
ZohoCorp ManageEngine OpManager 12.5 build125123
ZohoCorp ManageEngine OpManager 12.5 build125124
ZohoCorp ManageEngine OpManager 12.5 build125125
ZohoCorp ManageEngine OpManager 12.5 build125136
ZohoCorp ManageEngine OpManager 12.5 build125137
ZohoCorp ManageEngine OpManager 12.5 build125139
ZohoCorp ManageEngine OpManager 12.5 build125140
ZohoCorp ManageEngine OpManager 12.5 build125143
ZohoCorp ManageEngine OpManager 12.5 build125144
ZohoCorp ManageEngine OpManager 12.5 build125145
ZohoCorp ManageEngine OpManager 12.5 build125156
ZohoCorp ManageEngine OpManager 12.5 build125157
ZohoCorp ManageEngine OpManager 12.5 build125158
ZohoCorp ManageEngine OpManager 12.5 build125159
ZohoCorp ManageEngine OpManager 12.5 build125161
ZohoCorp ManageEngine OpManager 12.5 build125163
ZohoCorp ManageEngine OpManager 12.5 build125174
ZohoCorp ManageEngine OpManager 12.5 build125175
ZohoCorp ManageEngine OpManager 12.5 build125176
ZohoCorp ManageEngine OpManager 12.5 build125177
ZohoCorp ManageEngine OpManager 12.5 build125178
ZohoCorp ManageEngine OpManager 12.5 build125180
ZohoCorp ManageEngine OpManager 12.5 build125181
ZohoCorp ManageEngine OpManager 12.5 build125192
ZohoCorp ManageEngine OpManager 12.5 build125193
ZohoCorp ManageEngine OpManager 12.5 build125194
ZohoCorp ManageEngine OpManager 12.5 build125195
ZohoCorp ManageEngine OpManager 12.5 build125196
ZohoCorp ManageEngine OpManager 12.5 build125197
ZohoCorp ManageEngine OpManager 12.5 build125198
ZohoCorp ManageEngine OpManager 12.5 build125201
ZohoCorp ManageEngine OpManager 12.5 build125204
ZohoCorp ManageEngine OpManager 12.5 build125212
ZohoCorp ManageEngine OpManager 12.5 build125213
ZohoCorp ManageEngine OpManager 12.5 build125214
ZohoCorp ManageEngine OpManager 12.5 build125215
ZohoCorp ManageEngine OpManager 12.5 build125216
ZohoCorp ManageEngine OpManager 12.5 build125228
ZohoCorp ManageEngine OpManager 12.5 build125229
ZohoCorp ManageEngine OpManager 12.5 build125230
ZohoCorp ManageEngine OpManager 12.5 build125231
ZohoCorp ManageEngine OpManager 12.5 build125232
ZohoCorp ManageEngine OpManager 12.5 build125233
ZohoCorp ManageEngine OpManager 12.5 build125312
Vulnerability Description A directory traversal vulnerability in ZohoCorp ManageEngine OpManager allows remote attackers to delete any directory or directories on the OS, potentially causing a denial-of-service condition.

Protection Overview

This protection detects attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.

Security Gateway R81 / R80 / R77 / R75

  1. In the IPS tab, click Protections and find the ZohoCorp ManageEngine OpManager Directory Traversal (CVE-2021-20078) protection using the Search tool and Edit the protection's settings.
  2. Install policy on all Security Gateways.

This protection's log will contain the following information:

Attack Name:  Application Servers Protection Violation.
Attack Information:  ZohoCorp ManageEngine OpManager Directory Traversal (CVE-2021-20078)

×
  Feedback
This website uses cookies for its functionality and for analytics and marketing purposes. By continuing to use this website, you agree to the use of cookies. For more information, please read our Cookies Notice.
OK