CVE-2019-17602

CRITICAL

ManageEngine OpManager < 12.4 - SQL Injection via OPMDeviceDetailsServlet

Title source: llm
STIX 2.1

Description

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.

References (1)

Core 1
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://www.manageengine.com/network-monitoring/help/read-me-complete.html

Scores

CVSS v3 9.8
EPSS 0.4772
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (2)
zohocorp/manageengine_opmanager 12.4 (40 CPE variants)
zohocorp/manageengine_opmanager < 12.4
Published Oct 15, 2019
Tracked Since Feb 18, 2026