📦 Manageengine Opmanager

by Zohocorp

🔍 What is Manageengine Opmanager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-47211

CRITICAL CVSS 9.1 Jan 8, 2024

A directory traversal vulnerability in ManageEngine OpManager's uploadMib functionality allows attackers to create arbitrary files on the system by sending specially crafted HTTP requests with malicio...

CVE-2022-29535

CRITICAL CVSS 9.8 May 5, 2022

This vulnerability allows attackers to execute arbitrary SQL commands through default reports in Zoho ManageEngine OPManager. It affects all OPManager installations up to version 125588. Successful ex...

CVE-2021-41288

CRITICAL CVSS 9.8 Sep 30, 2021

CVE-2021-41288 is a critical SQL injection vulnerability in Zoho ManageEngine OpManager's getReportData API. Attackers can execute arbitrary SQL commands, potentially compromising the entire database....

CVE-2021-3287

CRITICAL CVSS 9.8 Apr 22, 2021

CVE-2021-3287 is an unauthenticated remote code execution vulnerability in Zoho ManageEngine OpManager caused by insecure Java deserialization. Attackers can exploit this to execute arbitrary code on ...

CVE-2021-20078

CRITICAL CVSS 9.1 Apr 1, 2021

CVE-2021-20078 is a path traversal vulnerability in ManageEngine OpManager's Spark Gateway component that allows remote attackers to delete arbitrary directories on the operating system. This affects ...

CVE-2020-28653

CRITICAL CVSS 9.8 Feb 3, 2021

This vulnerability allows remote attackers to execute arbitrary code on Zoho ManageEngine OpManager systems via the Smart Update Manager (SUM) servlet. It affects OpManager Stable builds before 125203...

CVE-2024-5466

HIGH CVSS 8.8 Aug 23, 2024

This vulnerability allows authenticated attackers to execute arbitrary code remotely on ManageEngine OpManager and Remote Monitoring and Management systems. Attackers can exploit the deploy agent opti...

CVE-2022-27908

HIGH CVSS 8.8 Apr 18, 2022

This vulnerability allows authenticated attackers to execute arbitrary SQL commands in Zoho ManageEngine OpManager's Inventory Reports module. Attackers with valid credentials can potentially access, ...