« Volver al listado

CVE-2024-36038

Estado: AplazadaMedia (6.3)—

Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-36038",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-36038",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-24T13:18:09.910935Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.8:build128248:*:*:*:*:*:*"
          ],
          "vendor": "ManageEngine",
          "product": "OpManager",
          "versions": [
            {
              "status": "affected",
              "version": "128234",
              "lessThan": "128248",
              "versionType": "128248"
            }
          ],
          "platforms": [
            "Windows",
            "Linux"
          ],
          "collectionURL": "https://www.manageengine.com/network-monitoring/download.html",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-06-24T12:15:09.630",
  "references": [
    {
      "url": "https://www.manageengine.com/itom/advisory/cve-2024-36038.html",
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02"
    },
    {
      "url": "https://www.manageengine.com/itom/advisory/cve-2024-36038.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option."
    },
    {
      "lang": "es",
      "value": "Las versiones de los productos Zoho ManageEngine ITOM de 128234 a 128248 se ven afectadas por la vulnerabilidad de cross-site scripting almacenado en la opción de servidor proxy."
    }
  ],
  "lastModified": "2026-06-17T07:36:00.680",
  "sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02"
}