VendorsZoho Corpmanageengine_opmanagerall versions
Vulnerabilities

Zoho Corp Manageengine Opmanager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

56CVEs
CVE-2022-36923
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
Published 2022-08-10 · Analyzed
7.5EPSS 0.071
CVE-2018-12997
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server without login by sending a specially crafted request to the server with the operation=copyfile&fileName= substring.
Published 2018-06-29 · Modified
7.5EPSS 0.066
CVE-2017-11559
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
Published 2019-05-23 · Modified
7.5EPSS 0.045
CVE-2017-11561
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
Published 2019-05-23 · Modified
6.5EPSS 0.020
CVE-2014-6036
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.
Published 2014-12-04 · Modified
6.41 PoCEPSS 0.363
CVE-2018-12998
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
Published 2018-06-29 · Modified
6.1EPSS 0.993
CVE-2018-18715
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
Published 2018-11-20 · Modified
6.1EPSS 0.028
CVE-2018-18716
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
Published 2018-11-20 · Modified
6.1EPSS 0.028
CVE-2018-20339
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
Published 2018-12-21 · Modified
6.1EPSS 0.024
CVE-2018-19288
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
Published 2018-11-15 · Modified
6.1EPSS 0.024
CVE-2018-18262
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
Published 2018-10-17 · Modified
6.1EPSS 0.020
CVE-2018-19921
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
Published 2018-12-06 · Modified
6.1EPSS 0.019
CVE-2022-43473
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
Published 2023-03-30 · Modified
5.8EPSS 0.198
CVE-2023-6105
ManageEngine Information Disclosure in Multiple Products
Published 2023-11-15 · Modified
5.5EPSS 0.007
CVE-2017-11560
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted by the application. Thus, an attacker can inject a malicious JavaScript payload inside the HTML file and upload it to the application.
Published 2019-05-23 · Modified
5.4EPSS 0.014
CVE-2014-6034
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 through 11.3, Social IT Plus 11.0, and IT360 10.4 and earlier allows remote attackers or remote authenticated users to write to and execute arbitrary WAR files via a .. (dot dot) in the regionID parameter.
Published 2014-12-04 · Modified
5.02 PoCEPSS 0.790
← Prev2 / 2