CVE-2021-40493
Description
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ManageEngine OpManager before build 125437 is vulnerable to SQL injection in the support diagnostics module via the pollingObject parameter, allowing attackers to execute arbitrary SQL commands.
Vulnerability
An SQL injection vulnerability exists in the support diagnostics module of Zoho ManageEngine OpManager [1]. The flaw is present in the getDataCollectionFailureReason API, specifically via the pollingObject parameter. Affected builds range from version 125140 up to 125436. The vulnerability was fixed in builds 125437 and 125453 [1].
Exploitation
An attacker can exploit this vulnerability by sending a crafted HTTP request to the getDataCollectionFailureReason API endpoint with a malicious pollingObject parameter [1]. The advisory does not specify authentication requirements, but the API is part of the support diagnostics module, which may be accessible to authenticated users or potentially without authentication.
Impact
Successful exploitation allows an attacker to execute arbitrary SQL queries against the underlying database [1]. This could result in unauthorized access to sensitive data, modification of database contents, and potentially remote code execution depending on the database user's privileges.
Mitigation
The vulnerability is fixed in OpManager builds 125437 and 125453, released on September 3, 2021 [1]. Users should upgrade to version 12.5.437 or later. No workarounds are provided in the advisory [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho ManageEngine/Zoho ManageEngine OpManagerdescription
- Range: <125437
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.manageengine.com/network-monitoring/security-updates/cve-2021-40493.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.