9.8

CVE-2018-20173

Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Opmanager Version12.3 Updatebuild12300
ZohocorpManageengine Opmanager Version12.3 Updatebuild123001
ZohocorpManageengine Opmanager Version12.3 Updatebuild123002
ZohocorpManageengine Opmanager Version12.3 Updatebuild123003
ZohocorpManageengine Opmanager Version12.3 Updatebuild123004
ZohocorpManageengine Opmanager Version12.3 Updatebuild123005
ZohocorpManageengine Opmanager Version12.3 Updatebuild123006
ZohocorpManageengine Opmanager Version12.3 Updatebuild123007
ZohocorpManageengine Opmanager Version12.3 Updatebuild123008
ZohocorpManageengine Opmanager Version12.3 Updatebuild123009
ZohocorpManageengine Opmanager Version12.3 Updatebuild123010
ZohocorpManageengine Opmanager Version12.3 Updatebuild123011
ZohocorpManageengine Opmanager Version12.3 Updatebuild123012
ZohocorpManageengine Opmanager Version12.3 Updatebuild123013
ZohocorpManageengine Opmanager Version12.3 Updatebuild123014
ZohocorpManageengine Opmanager Version12.3 Updatebuild123015
ZohocorpManageengine Opmanager Version12.3 Updatebuild123021
ZohocorpManageengine Opmanager Version12.3 Updatebuild123022
ZohocorpManageengine Opmanager Version12.3 Updatebuild123023
ZohocorpManageengine Opmanager Version12.3 Updatebuild123024
ZohocorpManageengine Opmanager Version12.3 Updatebuild123025
ZohocorpManageengine Opmanager Version12.3 Updatebuild123026
ZohocorpManageengine Opmanager Version12.3 Updatebuild123027
ZohocorpManageengine Opmanager Version12.3 Updatebuild123028
ZohocorpManageengine Opmanager Version12.3 Updatebuild123029
ZohocorpManageengine Opmanager Version12.3 Updatebuild123030
ZohocorpManageengine Opmanager Version12.3 Updatebuild123031
ZohocorpManageengine Opmanager Version12.3 Updatebuild123032
ZohocorpManageengine Opmanager Version12.3 Updatebuild123033
ZohocorpManageengine Opmanager Version12.3 Updatebuild123034
ZohocorpManageengine Opmanager Version12.3 Updatebuild123035
ZohocorpManageengine Opmanager Version12.3 Updatebuild123036
ZohocorpManageengine Opmanager Version12.3 Updatebuild123037
ZohocorpManageengine Opmanager Version12.3 Updatebuild123043
ZohocorpManageengine Opmanager Version12.3 Updatebuild123044
ZohocorpManageengine Opmanager Version12.3 Updatebuild123045
ZohocorpManageengine Opmanager Version12.3 Updatebuild123046
ZohocorpManageengine Opmanager Version12.3 Updatebuild123047
ZohocorpManageengine Opmanager Version12.3 Updatebuild123048
ZohocorpManageengine Opmanager Version12.3 Updatebuild123049
ZohocorpManageengine Opmanager Version12.3 Updatebuild123050
ZohocorpManageengine Opmanager Version12.3 Updatebuild123051
ZohocorpManageengine Opmanager Version12.3 Updatebuild123052
ZohocorpManageengine Opmanager Version12.3 Updatebuild123053
ZohocorpManageengine Opmanager Version12.3 Updatebuild123054
ZohocorpManageengine Opmanager Version12.3 Updatebuild123055
ZohocorpManageengine Opmanager Version12.3 Updatebuild123056
ZohocorpManageengine Opmanager Version12.3 Updatebuild123057
ZohocorpManageengine Opmanager Version12.3 Updatebuild123062
ZohocorpManageengine Opmanager Version12.3 Updatebuild123063
ZohocorpManageengine Opmanager Version12.3 Updatebuild123064
ZohocorpManageengine Opmanager Version12.3 Updatebuild123065
ZohocorpManageengine Opmanager Version12.3 Updatebuild123066
ZohocorpManageengine Opmanager Version12.3 Updatebuild123067
ZohocorpManageengine Opmanager Version12.3 Updatebuild123068
ZohocorpManageengine Opmanager Version12.3 Updatebuild123069
ZohocorpManageengine Opmanager Version12.3 Updatebuild123070
ZohocorpManageengine Opmanager Version12.3 Updatebuild123076
ZohocorpManageengine Opmanager Version12.3 Updatebuild123077
ZohocorpManageengine Opmanager Version12.3 Updatebuild123078
ZohocorpManageengine Opmanager Version12.3 Updatebuild123079
ZohocorpManageengine Opmanager Version12.3 Updatebuild123080
ZohocorpManageengine Opmanager Version12.3 Updatebuild123081
ZohocorpManageengine Opmanager Version12.3 Updatebuild123082
ZohocorpManageengine Opmanager Version12.3 Updatebuild123083
ZohocorpManageengine Opmanager Version12.3 Updatebuild123084
ZohocorpManageengine Opmanager Version12.3 Updatebuild123086
ZohocorpManageengine Opmanager Version12.3 Updatebuild123090
ZohocorpManageengine Opmanager Version12.3 Updatebuild123091
ZohocorpManageengine Opmanager Version12.3 Updatebuild123092
ZohocorpManageengine Opmanager Version12.3 Updatebuild123192
ZohocorpManageengine Opmanager Version12.3 Updatebuild123193
ZohocorpManageengine Opmanager Version12.3 Updatebuild123194
ZohocorpManageengine Opmanager Version12.3 Updatebuild123195
ZohocorpManageengine Opmanager Version12.3 Updatebuild123196
ZohocorpManageengine Opmanager Version12.3 Updatebuild123197
ZohocorpManageengine Opmanager Version12.3 Updatebuild123198
ZohocorpManageengine Opmanager Version12.3 Updatebuild123204
ZohocorpManageengine Opmanager Version12.3 Updatebuild123205
ZohocorpManageengine Opmanager Version12.3 Updatebuild123206
ZohocorpManageengine Opmanager Version12.3 Updatebuild123207
ZohocorpManageengine Opmanager Version12.3 Updatebuild123208
ZohocorpManageengine Opmanager Version12.3 Updatebuild123222
ZohocorpManageengine Opmanager Version12.3 Updatebuild123223
ZohocorpManageengine Opmanager Version12.3 Updatebuild123224
ZohocorpManageengine Opmanager Version12.3 Updatebuild123229
ZohocorpManageengine Opmanager Version12.3 Updatebuild123230
ZohocorpManageengine Opmanager Version12.3 Updatebuild123231
ZohocorpManageengine Opmanager Version12.3 Updatebuild123237
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.83% 0.937
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.