RULE(RULE ID:333543)

Rule General Information
Release Date: 2021-05-13
Rule Name: ManageEngine OpManager Remote Directory Deletion Vulnerability (CVE-2021-20078)
Severity:
CVE ID:
Rule Protection Details
Description: Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Others
Reference: https://www.tenable.com/security/research/tra-2021-10
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://www.tenable.com/security/research/tra-2021-10