CVE-2014-6036: Zohocorp ManageEngine IT360

Medium severity, CVSS 6.4. EPSS: 36.3% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.

Affected products

  • Zohocorp ManageEngine IT360: up to and including 10.4; version 10.3.0 only
  • Zohocorp ManageEngine Opmanager: up to and including 11.3
  • Zohocorp ManageEngine Social It Plus: version 11.0 only

Published 2014-12-04. Last modified 2026-06-17.