CVE-2014-7866: Zohocorp ManageEngine IT360

High severity, CVSS 7.5. EPSS: 79.8% chance of exploitation in the next 30 days.

Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.

Affected products

  • Zohocorp ManageEngine IT360: version 10.3.0 only; version 10.4 only
  • Zohocorp ManageEngine Opmanager: version 8.8 only; version 9.0 only; version 9.1 only; version 9.2 only; version 9.4 only; version 10.0 only; …
  • Zohocorp ManageEngine Social It Plus: version 11.0 only

Published 2014-12-10. Last modified 2026-06-17.