Zohocorp

Manageengine Opmanager

57 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 12.83%
  • Published 05.11.2018 09:29:00
  • Last modified 21.11.2024 03:56:55

Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.

  • EPSS 4.68%
  • Published 23.10.2018 21:30:54
  • Last modified 21.11.2024 03:55:59

Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.

  • EPSS 1.21%
  • Published 17.10.2018 14:29:01
  • Last modified 21.11.2024 03:55:37

Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.

Exploit
  • EPSS 35.83%
  • Published 21.09.2018 03:29:00
  • Last modified 21.11.2024 03:54:10

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via ...

  • EPSS 7.39%
  • Published 20.09.2018 07:29:00
  • Last modified 21.11.2024 03:54:08

Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.

Exploit
  • EPSS 73%
  • Published 29.06.2018 12:29:00
  • Last modified 21.11.2024 03:46:13

A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer befor...

Exploit
  • EPSS 3.69%
  • Published 29.06.2018 12:29:00
  • Last modified 21.11.2024 03:46:13

Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before b...

  • EPSS 1.67%
  • Published 04.08.2017 00:29:00
  • Last modified 20.04.2025 01:37:25

Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a...

Exploit
  • EPSS 77.55%
  • Published 09.10.2015 14:59:08
  • Last modified 12.04.2025 10:46:40

PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."

Exploit
  • EPSS 80.85%
  • Published 09.10.2015 14:59:06
  • Last modified 12.04.2025 10:46:40

ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.