CVE-2014-9372: ManageEngine Password Manager Pro
Medium severity, CVSS 6.4. EPSS: 2.4% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
Affected products
- ManageEngine Password Manager Pro: up to and including 7.1
Published 2014-12-16. Last modified 2026-06-17.