Summary
Detail | |||
---|---|---|---|
Vendor | Zohocorp | First view | 2022-04-18 |
Product | Manageengine Opmanager | Last view | 2024-01-08 |
Version | 12.5 | Type | Application |
Update | build125568 | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:zohocorp:manageengine_opmanager |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
8.6 | 2024-01-08 | CVE-2023-47211 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. |
8.8 | 2023-05-04 | CVE-2023-31099 | Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. |
5.4 | 2023-03-30 | CVE-2022-43473 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability. |
8.8 | 2022-08-29 | CVE-2022-38772 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature. |
8.2 | 2022-07-18 | CVE-2022-35404 | ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine. |
9.8 | 2022-05-05 | CVE-2022-29535 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. |
8.8 | 2022-04-18 | CVE-2022-27908 | Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
40% (2) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
20% (1) | CWE-611 | Information Leak Through XML External Entity File Disclosure |
20% (1) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
20% (1) | CWE-20 | Improper Input Validation |