CVE-2021-42099

CVSS V2 High 7.5 CVSS V3 Critical 9.8
Description
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
Overview
  • CVE ID
  • CVE-2021-42099
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2021-11-30T19:15:09
  • Last Modified Date
  • 2021-12-06T18:20:53
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:-:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4000:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4001:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4002:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4003:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4004:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4005:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4007:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4008:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4009:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4010:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4011:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4012:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4013:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4014:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4100:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4101:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4102:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4103:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4104:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4105:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4106:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4108:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4109:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4110:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4111:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4112:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4113:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4115:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4116:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4117:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4118:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4119:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4200:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4201:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4202:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4203:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4204:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4205:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4206:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4207:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4208:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4209:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4210:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4211:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4212:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4213:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4214:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4215:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4216:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4217:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4218:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4219:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4220:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4221:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4222:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4300:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4301:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4302:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4303:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4304:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4305:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4306:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4308:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4309:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4310:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4311:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4312:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4316:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4317:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4318:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4319:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4320:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4321:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4322:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4324:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4325:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4327:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4328:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4329:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4330:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4331:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4332:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4333:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4334:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4335:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4336:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4400:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4401:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4402:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4403:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4406:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4407:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4408:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4410:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4411:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4412:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4413:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4414:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4415:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4416:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4417:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4418:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_m365_manager_plus:build_4419:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 9.8
  • Base Severity
  • CRITICAL
  • Exploitability Score
  • 3.9
  • Impact Score
  • 5.9
References
History
Created Old Value New Value Data Type Notes
2022-05-10 06:42:55 Added to TrackCVE
2022-12-05 15:18:10 2021-11-30T19:15Z 2021-11-30T19:15:09 CVE Published Date updated
2022-12-05 15:18:10 2021-12-06T18:20:53 CVE Modified Date updated
2022-12-05 15:18:10 Analyzed Vulnerability Status updated