ManageEngine Log360
cpe:2.3:a:zohocorp:manageengine_log360:*:*:*:*:*:*:*
- >= 13000, <= 13013
An authentication bypass vulnerability has been identified in ManageEngine Log360, affecting versions 13000 through 13013. This vulnerability arises from improper filter configuration, which allows certain actions to bypass authentication requirements. As a result, unauthorized users may gain access to restricted data and operations via the exposed V1 APIs.
Exploitation of this vulnerability allows for authentication bypass on the exposed V1 APIs, potentially leading to unauthorized access to data and operations.
Users can update to Log360 build 13017 or the latest version using the available service pack. Instructions for downloading the service pack are available on the ManageEngine Log360 website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.