ManageEngine OpManager MSP
by Zoho
CVEs (33)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-13818 | Hig | 0.52 | 7.5 | 0.37 | Jun 4, 2020 | In Zoho ManageEngine OpManager before 125144, when is used, directory traversal validation can be bypassed. | ||
| CVE-2019-17421 | Hig | 0.51 | 7.8 | 0.01 | Nov 21, 2019 | Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload. | ||
| CVE-2020-11527 | Hig | 0.50 | 7.5 | 0.09 | Apr 4, 2020 | In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files. | ||
| CVE-2022-36923 | Hig | 0.49 | 7.5 | 0.07 | Aug 10, 2022 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and… | ||
| CVE-2017-11559 | Hig | 0.49 | 7.5 | 0.04 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack. | ||
| CVE-2017-11561 | Med | 0.42 | 6.5 | 0.02 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell. | ||
| CVE-2018-20339 | Med | 0.40 | 6.1 | 0.02 | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. | ||
| CVE-2018-19921 | Med | 0.40 | 6.1 | 0.02 | Dec 6, 2018 | Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller. | ||
| CVE-2018-18716 | Med | 0.40 | 6.1 | 0.03 | Nov 20, 2018 | Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability. | ||
| CVE-2018-18715 | Med | 0.40 | 6.1 | 0.03 | Nov 20, 2018 | Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. | ||
| CVE-2018-19288 | Med | 0.40 | 6.1 | 0.02 | Nov 15, 2018 | Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API. | ||
| CVE-2018-18262 | Med | 0.40 | 6.1 | 0.02 | Oct 17, 2018 | Zoho ManageEngine OpManager 12.3 before build 123214 has XSS. | ||
| CVE-2017-11560 | Med | 0.35 | 5.4 | 0.01 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted… |
- risk 0.52cvss 7.5epss 0.37
In Zoho ManageEngine OpManager before 125144, when is used, directory traversal validation can be bypassed.
- risk 0.51cvss 7.8epss 0.01
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
- risk 0.50cvss 7.5epss 0.09
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
- risk 0.49cvss 7.5epss 0.07
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and…
- risk 0.49cvss 7.5epss 0.04
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
- risk 0.42cvss 6.5epss 0.02
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted…
Page 2 of 2