Zoho Vulnerabilities and Affected Products
Vulnerabilities associated with manageengine_opmanager.
Products
Clear product- ManageEngine6 vulnerabilities
- manageengine_opmanager3 vulnerabilities
- ManageEngine ServiceDesk2 vulnerabilities
- campaigns1 vulnerability
- Desktop Central1 vulnerability
- firewall_analyzer1 vulnerability
- ManageEngine ServiceDesk Plus (SDP)1 vulnerability
- ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus1 vulnerability
- manageengine_access_manager_plus1 vulnerability
- manageengine_adaudit_plus1 vulnerability
- manageengine_admanager_plus1 vulnerability
- manageengine_adselfservice_plus1 vulnerability
- manageengine_firewall_analyzer1 vulnerability
- Password Manager Pro (PMP)1 vulnerability
- Zoho CRM Lead Magnet1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-3287CRITICAL | Zoho manageengine_opmanager Deserialization of Untrusted DataZoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. | CVSS9.8v3.1 | EPSS51.3% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-28653CRITICAL | Zoho ManageEngine OpManager Smart Update Manager Servlet Remote Code ExecutionZoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet. Feb 3, 20211 related artifact | CVSS9.8v3.1 | EPSS78.7% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-17283HIGH | Zoho manageengine_opmanager Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter. | CVSS7.5v3.0 | EPSS66.3% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |