ManageEngine Vulnerabilities and Affected Products
Vulnerabilities associated with OpManager.
Products
Clear product- ADAudit Plus35 vulnerabilities
- adaudit_plus25 vulnerabilities
- Applications Manager8 vulnerabilities
- Exchange Reporter Plus8 vulnerabilities
- ADSelfService Plus5 vulnerabilities
- OpManager5 vulnerabilities
- Endpoint Central4 vulnerabilities
- ServiceDesk Plus MSP4 vulnerabilities
- Desktop Central3 vulnerabilities
- exchange_reporter_plus3 vulnerabilities
- PAM3603 vulnerabilities
- ServiceDesk Plus3 vulnerabilities
- SupportCenter Plus3 vulnerabilities
- ADManager Plus2 vulnerabilities
- Analytics Plus2 vulnerabilities
- Asset Explorer2 vulnerabilities
- DDI Central2 vulnerabilities
- servicedesk2 vulnerabilities
- Access Manager Plus1 vulnerability
- desktop_central1 vulnerability
- OpManager, OpManager Plus, OpManager MSP, OpManager Enterprise Edition1 vulnerability
- OpManager, Remote Monitoring and Management1 vulnerability
- Password Manager Pro1 vulnerability
- password_manager_pro1 vulnerability
- Service Desk Plus1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-41437MEDIUM | Reflected XSSZohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page. CWE-79Jun 9, 2025 | CVSS4.3v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-6748HIGH | SQL InjectionZohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring. CWE-89Jul 29, 2024 | CVSS8.3v3.1 | EPSS23.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-36038MEDIUM | Stored XSSZoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option. CWE-79Jun 24, 2024 | CVSS6.3v3.1 | EPSS1.43% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47211CRITICAL | ManageEngine OpManager - Directory TraversalA directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | CVSS9.1v3.1 | EPSS47% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2022-43473MEDIUM | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability. CWE-611Mar 30, 2023 | CVSS5.8v3.1 | EPSS19.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |