threat
engine
.sh
Back
·
··:··
Home
/
Product
/
zohocorp manageengine opmanager
Product
zohocorp manageengine opmanager
59 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-5466
<= 12.7
Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticat
8.8
HIGH
CVE-2023-47211
< 12.7
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted
9.1
CRITICAL
CVE-2023-6105
< 12.5
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed.
5.5
MEDIUM
CVE-2023-31099
< 12.6
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
8.8
HIGH
CVE-2022-43473
< 12.6
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A s
5.8
MEDIUM
CVE-2022-38772
all versions
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 12
8.8
HIGH
CVE-2022-37024
all versions
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 20
8.8
HIGH
CVE-2022-36923
all versions
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, an
7.5
HIGH
CVE-2022-35404
< 12.5
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory
8.2
HIGH
CVE-2022-29535
< 12.5
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
9.8
CRITICAL
CVE-2022-27908
< 12.5
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Report
8.8
HIGH
CVE-2021-44514
all versions
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
9.8
CRITICAL
CVE-2021-41075
< 12.5
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
9.8
CRITICAL
CVE-2021-40493
< 12.5
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the po
9.8
CRITICAL
CVE-2021-41288
<= 12.4
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
9.8
CRITICAL
CVE-2020-19554
<= 12.5.174
Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS pa
6.1
MEDIUM
CVE-2021-3287
< 12.5
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserializ
9.8
CRITICAL
CVE-2021-20078
< 12.5
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal iss
9.1
CRITICAL
CVE-2020-28653
< 12.5
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Sma
9.8
CRITICAL
CVE-2020-13818
< 12.5
In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
7.5
HIGH
CVE-2020-12116
<= 12.3
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read
7.5
HIGH
CVE-2020-11946
all versions
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
7.5
HIGH
CVE-2020-11527
< 12.4
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitr
7.5
HIGH
CVE-2020-10541
< 12.4.179
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API reque
9.8
CRITICAL
CVE-2014-7863
>= 8 and <= 11.5
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8
7.5
HIGH
CVE-2019-17421
all versions
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12
7.8
HIGH
CVE-2019-17602
< 12.4
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to S
9.8
CRITICAL
CVE-2019-15106
<= 12.4.034
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and ex
9.8
CRITICAL
CVE-2019-12133
all versions
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\Manag
7.8
HIGH
CVE-2017-11560
all versions
An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can
5.4
MEDIUM
CVE-2017-11559
all versions
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and
7.5
HIGH
CVE-2017-11561
all versions
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "
6.5
MEDIUM
CVE-2018-20339
all versions
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
6.1
MEDIUM
CVE-2018-20338
all versions
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
9.8
CRITICAL
CVE-2018-20173
all versions
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
9.8
CRITICAL
CVE-2018-19921
all versions
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
6.1
MEDIUM
CVE-2018-18716
all versions
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
6.1
MEDIUM
CVE-2018-18715
all versions
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
6.1
MEDIUM
CVE-2018-19288
all versions
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
6.1
MEDIUM
CVE-2018-18980
< 12.3.214
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager befor
7.5
HIGH
CVE-2018-18949
all versions
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
9.8
CRITICAL
CVE-2018-18475
all versions
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
9.8
CRITICAL
CVE-2018-18262
all versions
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
6.1
MEDIUM
CVE-2018-17283
< 12.3
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated
7.5
HIGH
CVE-2018-17243
< 12.3
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
9.8
CRITICAL
CVE-2018-12998
all versions
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configurat
6.1
MEDIUM
CVE-2018-12997
all versions
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration
7.5
HIGH
CVE-2015-9107
all versions
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monito
9.8
CRITICAL
CVE-2015-7766
<= 11.5
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restr
CVE-2015-7765
all versions
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, wh
CVE-2014-7864
all versions
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 thr
CVE-2014-7866
all versions
Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and
CVE-2014-7868
all versions
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0
CVE-2014-7867
all versions
SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpMana
CVE-2014-6036
<= 11.3
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus
CVE-2014-6035
<= 11.3
Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remot
CVE-2014-6034
all versions
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO Manage
CVE-2007-5891
all versions
Multiple cross-site scripting (XSS) vulnerabilities in jsp/Login.do in ManageEngine OpManager MSP Edition and OpManager 7.0 allow
CVE-2006-2343
all versions
Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine OpManager 6.0 allows remote attackers to inject arbitrary we
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin