Description
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:47:04.101Z
Reserved: 2018-09-20T00:00:00.000Z
Link: CVE-2018-17283
No data.
Status : Modified
Published: 2018-09-21T03:29:00.407
Modified: 2024-11-21T03:54:10.620
Link: CVE-2018-17283
No data.
OpenCVE Enrichment
No data.
Weaknesses