Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zohocorp manageengine opmanager vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2020-11946
Zoho ManageEngine OpManager prior to 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
Zohocorp Manageengine Opmanager 12.5
5
CVSSv2
CVE-2020-11527
In Zoho ManageEngine OpManager prior to 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
Zohocorp Manageengine Opmanager
Zohocorp Manageengine Opmanager 12.4
5
CVSSv2
CVE-2014-7863
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager prior to 11.9 build 11912, OpManager 8 up to and including 11.5 build 11400, and IT360 10.5 and previous versions does not properly restrict access, which allows remote attackers and rem...
Zohocorp Manageengine It360
Zohocorp Manageengine Opmanager
Zohocorp Manageengine Applications Manager
1 EDB exploit
5
CVSSv2
CVE-2017-11559
An issue exists in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
Zohocorp Manageengine Opmanager 12.2
5
CVSSv2
CVE-2018-18980
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager prior to 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local...
Zohocorp Manageengine Network Configuration Manager
Zohocorp Manageengine Opmanager
5
CVSSv2
CVE-2018-17283
Zoho ManageEngine OpManager prior to 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser o...
Zohocorp Manageengine Opmanager
5
CVSSv2
CVE-2018-12997
Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows malicious u...
Zohocorp Manageengine Netflow Analyzer -
Zohocorp Firewall Analyzer -
Zohocorp Manageengine Opmanager -
Zohocorp Manageengine Oputils -
Zohocorp Manageengine Network Configuration Manager -
5
CVSSv2
CVE-2015-9107
Zoho ManageEngine OpManager 11 up to and including 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a univers...
Zohocorp Manageengine Opmanager 11.5
Zohocorp Manageengine Opmanager 11.3
Zohocorp Manageengine Opmanager 11.4
Zohocorp Manageengine Opmanager 11.0
Zohocorp Manageengine Opmanager 11.1
Zohocorp Manageengine Opmanager 11.6
Zohocorp Manageengine Opmanager 12.2
Zohocorp Manageengine Opmanager 11.2
5
CVSSv2
CVE-2014-6034
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 up to and including 11.3, Social IT Plus 11.0, and IT360 10.4 and previous versions allows remote attackers or remote authenticat...
Zohocorp Manageengine Social It Plus 11.0
Zohocorp Manageengine It360
Zohocorp Manageengine Opmanager 9.0
Zohocorp Manageengine Opmanager 8.8
Zohocorp Manageengine Opmanager 11.3
Zohocorp Manageengine Opmanager 9.4
Zohocorp Manageengine Opmanager 11.0
Zohocorp Manageengine Opmanager 10.2
Zohocorp Manageengine Opmanager 11.1
Zohocorp Manageengine Opmanager 9.1
Zohocorp Manageengine Opmanager 9.2
Zohocorp Manageengine Opmanager 10.1
Zohocorp Manageengine Opmanager 11.2
Zohocorp Manageengine Opmanager 10.0
2 EDB exploits
4.3
CVSSv2
CVE-2018-20339
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
Zohocorp Manageengine Opmanager 12.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »