Showing 3 vulnerabilities on this page for manageengine_opmanager

Signals CISA KEV Ransomware Nuclei
Zoho vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Zoho manageengine_opmanager Deserialization of Untrusted Data

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

CWE-502Apr 22, 20211 related artifact
CVSS9.8v3.1EPSS51.3%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Zoho ManageEngine OpManager Smart Update Manager Servlet Remote Code Execution

Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

Feb 3, 20211 related artifact
CVSS9.8v3.1EPSS78.7%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Zoho manageengine_opmanager Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.

CWE-89Sep 21, 20181 related artifact
CVSS7.5v3.0EPSS66.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX