VendorsZoho Corpmanageengine_firewall_analyzer12.2
Vulnerabilities

Zoho Corp oration ManageEngine Firewall Analyzer 12.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-11678
The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.
Published 2019-05-02 · Modified
9.8EPSS 0.095
CVE-2019-11677
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
Published 2019-05-02 · Modified
9.8EPSS 0.094
CVE-2017-14123
Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated by /itplus/FileStorage/302/shell.jsp.
Published 2017-09-04 · Modified
9.0EPSS 0.061
CVE-2019-11676
The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.
Published 2019-05-02 · Modified
6.1EPSS 0.019