NA

CVE-2022-43473

Published: 30/03/2023 Updated: 07/11/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zohocorp manageengine opmanager 12.6

zohocorp manageengine opmanager

zohocorp manageengine opmanager plus 12.6

zohocorp manageengine opmanager plus

zohocorp manageengine opmanager msp 12.6

zohocorp manageengine opmanager msp