peter bassill · operator
$ cve CVE-2014-5445 JSON

CVE-2014-5445 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 98% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS98.01% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2014-12-04
Last modified2026-06-17

Affected (2)

VendorProduct
zohocorpmanageengine it360
zohocorpmanageengine netflow analyzer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD