CVE-2024-9100

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Oct 3, 2024
Updated: Oct 4, 2024
CWE ID 22

Summary

CVE-2024-9100 is a newly disclosed vulnerability affecting ManageEngine Analytics Plus versions prior to 5410 and Zoho Analytics On-Premise versions below 5410. This issue involves path traversal, which allows attackers to navigate outside of intended directories, potentially accessing sensitive files or data. Successful exploitation could lead to unauthorized system access or data exfiltration. Users are urged to update their systems to the latest versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share