CVE-2019-15106
CRITICALZohocorp Manageengine Opmanager < 12.4.034 - Missing Authentication
Title source: ruleDescription
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.
Exploits (1)
References (4)
Scores
CVSS v3
9.8
EPSS
0.3724
EPSS Percentile
97.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (1)
zohocorp/manageengine_opmanager
< 12.4.034
Published
Aug 16, 2019
Tracked Since
Feb 18, 2026