RULE(RULE ID:331000)

Rule General Information
Release Date: 2020-09-01
Rule Name: Zoho ManageEngine OpManager fluidicv2 UI Directory Traversal Vulnerability (CVE-2020-12116)
Severity:
CVE ID:
Rule Protection Details
Description: Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Others
Reference: https://www.manageengine.com/network-monitoring/help/read-me-complete.html
https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125125
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.manageengine.com/network-monitoring/help/read-me-complete.html