CVE-2021-40493

CRITICAL

Zoho ManageEngine OpManager <125437 - SQL Injection

Title source: llm
STIX 2.1

Description

Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.

References (1)

Core 1

Scores

CVSS v3 9.8
EPSS 0.3877
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
zohocorp/manageengine_opmanager 12.5 (50 CPE variants)
Published Oct 13, 2021
Tracked Since Feb 18, 2026