Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_eventlog_analyzer | 12.1.4-12146 | 12.1.4-12146.x |
| zohocorp / manageengine_eventlog_analyzer | 12.1.4-12145 | 12.1.4-12145.x |
| zohocorp / manageengine_eventlog_analyzer | 12.1.4-12141 | 12.1.4-12141.x |
| zohocorp / manageengine_eventlog_analyzer | - | 12.1.4 |
| zohocorp / manageengine_eventlog_analyzer | 12.1.4 | 12.1.4.x |