VYPR
Unrated severityNVD Advisory· Published Oct 13, 2021· Updated Aug 4, 2024

CVE-2021-40493

CVE-2021-40493

Description

Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

ManageEngine OpManager before build 125437 is vulnerable to SQL injection in the support diagnostics module via the pollingObject parameter, allowing attackers to execute arbitrary SQL commands.

Vulnerability

An SQL injection vulnerability exists in the support diagnostics module of Zoho ManageEngine OpManager [1]. The flaw is present in the getDataCollectionFailureReason API, specifically via the pollingObject parameter. Affected builds range from version 125140 up to 125436. The vulnerability was fixed in builds 125437 and 125453 [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the getDataCollectionFailureReason API endpoint with a malicious pollingObject parameter [1]. The advisory does not specify authentication requirements, but the API is part of the support diagnostics module, which may be accessible to authenticated users or potentially without authentication.

Impact

Successful exploitation allows an attacker to execute arbitrary SQL queries against the underlying database [1]. This could result in unauthorized access to sensitive data, modification of database contents, and potentially remote code execution depending on the database user's privileges.

Mitigation

The vulnerability is fixed in OpManager builds 125437 and 125453, released on September 3, 2021 [1]. Users should upgrade to version 12.5.437 or later. No workarounds are provided in the advisory [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.