7.5

CVE-2020-11946

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Opmanager Version12.5 Updatebuild125000
ZohocorpManageengine Opmanager Version12.5 Updatebuild125002
ZohocorpManageengine Opmanager Version12.5 Updatebuild125100
ZohocorpManageengine Opmanager Version12.5 Updatebuild125101
ZohocorpManageengine Opmanager Version12.5 Updatebuild125102
ZohocorpManageengine Opmanager Version12.5 Updatebuild125108
ZohocorpManageengine Opmanager Version12.5 Updatebuild125110
ZohocorpManageengine Opmanager Version12.5 Updatebuild125111
ZohocorpManageengine Opmanager Version12.5 Updatebuild125112
ZohocorpManageengine Opmanager Version12.5 Updatebuild125113
ZohocorpManageengine Opmanager Version12.5 Updatebuild125114
ZohocorpManageengine Opmanager Version12.5 Updatebuild125116
ZohocorpManageengine Opmanager Version12.5 Updatebuild125117
ZohocorpManageengine Opmanager Version12.5 Updatebuild125118
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 67.01% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.