CVE-2014-6035: Zohocorp ManageEngine Opmanager
High severity, CVSS 7.5. EPSS: 28.8% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to write and execute arbitrary files via a .. (dot dot) in the FILENAME parameter.
Affected products
- Zohocorp ManageEngine Opmanager: up to and including 11.3; version 11.4 only
Published 2014-12-04. Last modified 2026-06-17.