« Volver al listado

Zohocorp

Zohocorp Manageengine Opmanager: vulnerabilidades y CVE

Zohocorp Manageengine Opmanager tiene 63 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 17 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE63
Últimos 12 meses5
Críticas17
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-76980Alta (7.4)0.39%—23 sept 2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
CVE-2026-75825Alta (8.8)1.1%—23 sept 2026
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
CVE-2026-15358Alta (7.5)1.1%—23 sept 2026
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
CVE-2026-12370Alta (7.6)1.5%—23 sept 2026
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could…
CVE-2025-9226Media (4.6)0.48%—30 ene 2026
Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.
CVE-2025-41437Media (4.3)0.25%—9 jun 2025
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.
CVE-2024-5466Alta (8.8)7.0%—23 ago 2024
Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
CVE-2024-38870Baja (3.5)0.28%—17 jul 2024
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to Stored XSS vulnerability in…
CVE-2023-47211Alta (8.6)47%—8 ene 2024
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB…
CVE-2023-6105Media (5.5)0.69%—15 nov 2023
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product…
CVE-2023-31099Alta (8.8)82%—4 may 2023
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
CVE-2022-43473Media (5.4)20%—30 mar 2023
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload…
CVE-2022-38772Alta (8.8)78%—29 ago 2022
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that…
CVE-2022-37024Alta (8.8)80%—10 ago 2022
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated…
CVE-2022-36923Alta (7.5)7.1%—10 ago 2022
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow…
CVE-2022-35404Alta (8.2)2.9%—18 jul 2022
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
CVE-2022-29535Crítica (9.8)92%—5 may 2022
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
CVE-2022-27908Alta (8.8)36%—18 abr 2022
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.
CVE-2021-44514Crítica (9.8)5.5%—9 dic 2021
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
CVE-2021-41075Crítica (9.8)3.4%—13 oct 2021
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
CVE-2021-40493Crítica (9.8)50%—13 oct 2021
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
CVE-2021-41288Crítica (9.8)80%—30 sept 2021
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
CVE-2021-3287Crítica (9.8)51%—22 abr 2021
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
CVE-2021-20078Crítica (9.1)60%—1 abr 2021
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any…
CVE-2020-28653Crítica (9.8)79%—3 feb 2021
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
CVE-2020-13818Alta (7.5)37%—4 jun 2020
In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
CVE-2020-12116Alta (7.5)97%—7 may 2020
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
CVE-2020-11946Alta (7.5)52%—20 abr 2020
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
CVE-2020-11527Alta (7.5)9.5%—4 abr 2020
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
CVE-2020-10541Crítica (9.8)10%—13 mar 2020
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services3
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter1
  4. T1078 Valid Accounts1
  5. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Zohocorp