a malicious XML payload to trigger this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-46474 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability. |
Tue, 11 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-02-11T19:14:03.416Z
Reserved: 2022-12-05T20:53:36.058Z
Link: CVE-2022-43473
Updated: 2024-08-03T13:32:59.643Z
Status : Modified
Published: 2023-03-30T17:15:06.750
Modified: 2024-11-21T07:26:33.497
Link: CVE-2022-43473
No data.
OpenCVE Enrichment
No data.
EUVD