← Vulnerability feed

Vulnerability record · CVE-2023-47211 · published 8 January 2024

CVE-2023-47211: ManageEngine OpManager uploadMib path traversal allows arbitrary file creation

Zohocorp · Manageengine Firewall Analyzer

The uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file can write files to arbitrary locations. Because the write is unauthenticated and can reach outside the application's intended directory, it is a serious integrity risk for exposed instances.

8.6 CVSS 3.1 High EPSS 47% · top 1.2% CWE-22 · Path traversal
8.6CVSS 3.1 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable arbitrary file creation with a high EPSS score and public exploit detail, though not in KEV.

What it is

The uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file can write files to arbitrary locations. Because the write is unauthenticated and can reach outside the application's intended directory, it is a serious integrity risk for exposed instances.

Impact

An attacker can create arbitrary files on the server, which can lead to code execution or configuration tampering depending on what the attacker can write and where. The CVSS vector shows high integrity impact with no confidentiality or availability impact.

Attack surface

Reachable over the network through the uploadMib HTTP endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description confirms the trigger is a malicious MIB file sent in a request.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.47 (98.8th percentile) and the Talos reference is tagged Exploit, indicating public exploit detail exists. No ransomware usage is documented.

What to do

  • Apply the vendor fix referenced in the ManageEngine advisory for CVE-2023-47211.
  • Restrict network access to the OpManager uploadMib endpoint to trusted management networks only.
  • Run the product with least privilege so arbitrary file writes cannot reach sensitive paths.
  • Audit file system changes in and around the OpManager installation for unexpected files.
  • Monitor vendor advisories for the other listed ManageEngine products sharing this code path.

Detection

  • Alert on HTTP requests to the uploadMib endpoint from untrusted sources.
  • Monitor for new or modified files in web-accessible and application directories.
  • Inspect MIB upload payloads for traversal sequences such as ../ in filenames.
  • Correlate file creation events with OpManager process activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-47211 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-29535Zoho ManageEngine OPManager SQL injection in default reportsZoho ManageEngine OPManager through build 125588 contains a SQL injection flaw reachable through a few default reports. Because the vulnerable path i…EPSS 92%analysed9.8CVE-2021-44514Zohocorp manageengine opmanager improper authentication vulnerabilityOpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.EPSS 5.4%9.8CVE-2021-43319Zohocorp manageengine network configuration manager command injection vulnerabilityZoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.EPSS 21%9.8CVE-2021-41080Zohocorp manageengine network configuration manager sql injection vulnerabilityZoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.EPSS 4.6%9.8CVE-2021-41081ManageEngine Network Configuration Manager SQL injection in configuration searchZoho ManageEngine Network Configuration Manager before build 125465 contains a SQL injection flaw in a configuration search function. Because the que…EPSS 64%analysed9.8CVE-2021-40493Zoho ManageEngine OpManager SQL injection in diagnostics APIZoho ManageEngine OpManager before build 125437 contains a SQL injection in the support diagnostics module, reached through the pollingObject paramet…EPSS 50%analysed9.8CVE-2021-41075Zohocorp manageengine opmanager sql injection vulnerabilityThe NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.EPSS 3.4%9.8CVE-2021-41288Zoho ManageEngine OpManager getReportData API SQL injectionZoho ManageEngine OpManager build 125466 and below contains a SQL injection flaw in the getReportData API. Because the endpoint is network-reachable …EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2023-47211), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.