« Back to list

CVE-2019-17602

Status: ModifiedCritical (9.8)—

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2019-17602",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-10-15T21:15:11.127",
  "references": [
    {
      "url": "https://www.manageengine.com/network-monitoring/help/read-me-complete.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.manageengine.com/network-monitoring/help/read-me-complete.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated."
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en Zoho ManageEngine OpManager versiones anteriores a 12.4 build 124089. El servlet OPMDeviceDetailsServlet es propenso a la inyección SQL. Dependiendo de la configuración, esta vulnerabilidad podría ser explotada no autenticado o autenticado."
    }
  ],
  "lastModified": "2026-06-17T02:24:15.737",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC6C8B88-B295-48DB-859A-7AF8E9027F62",
              "versionEndExcluding": "12.4"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B666DF1F-0EF8-41F0-9EA0-EB104F87405F"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124000:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B7042C9-FD7C-4A83-A755-1429D3CEF91D"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124011:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86F61865-FB7B-4F12-B8EF-81A1DFB5E7E9"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124012:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D81E915-18CC-4419-879D-A2D90472F526"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124013:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B9314BA-7CA4-46C2-9ADD-AA15101081FB"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124014:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A94FB0E-7487-4E18-A7AD-19E47B03BF1C"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124015:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D99A8A01-8EDC-4AE6-8ED9-C7AF12DEDA62"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124016:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44A9BF34-7B3B-4B5F-AEFD-AA7434C6A682"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124022:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33068139-B994-4145-B73A-2344A699A0A0"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124023:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B798718E-3E01-4F3D-AD43-9BA7939E2EE0"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124024:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0C42019-0D5A-4938-87AB-F787C55E9834"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124025:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "373AA6C3-DA45-4CCD-88EF-859858732FDB"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124026:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13E24695-F223-4F62-B344-4CCB0BBE1050"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124027:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8EDB65B-34E1-4F89-B2E0-CEE13F39DA90"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124030:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8F7F90C-57BB-4E2F-BD79-1F56375A4E73"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124033:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1343F39-5FAA-4EB7-B95A-5D5133AD5717"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124037:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C23F2AB2-714D-4548-B9F9-315CE31CF573"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124039:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC8CDE36-EC3C-4F61-872C-8DD33688E0E3"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124040:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D790A131-CA15-42A1-8F35-3DCF27D51060"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124041:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C91F973F-3910-41E6-9D2F-3506E8EF5A0A"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124042:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "471FFC26-5DE7-42C6-B30B-EF5D1E1A35C2"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124043:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5407B79-C1DF-481E-83A3-BCE36BEE29E3"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124051:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F09EF7FD-47EB-4989-8805-74EC075F91AD"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124053:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F91FCCC4-C8C0-49B2-86C7-B2896D72F019"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124054:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7679A19-1874-4E97-87A5-60903A549A26"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124056:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3B991A7-452F-46C6-AB37-78137A7B27CA"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124058:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66A7CEE9-8647-462A-8F50-9159132E01FC"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124065:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28D368E2-FBB1-4DC2-BDBF-7A4F994A14F8"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124066:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9F3220A-D461-4412-9F73-B74EB299DBA1"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124067:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7442E3D2-83CC-4F75-89E3-64BAE5937722"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124069:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07B87F17-6AF0-4545-9527-154E0C6483C7"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124070:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B565B110-9A53-4BA1-BAB9-C6C16DEECD2F"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124071:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA46F3B7-0650-4630-9005-1FAC1EC22EE0"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124074:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8706C9CD-0D79-4661-B0C5-AB1813DE1F0F"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124075:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BACB527-2F9E-4C6B-8C7B-696EAD5251FC"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124081:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC9D8F85-EFB8-4D0E-BD8F-6DBE239559F0"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124082:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0297A0EA-43F2-4AD0-BC73-E6014F1F74BD"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124085:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA5F1F18-247B-4081-8B53-E34B1512D47F"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124086:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2B8F85FF-78A7-4BF4-83C2-FC3ABFBC8715"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124087:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1C1A1836-D054-4B96-890E-E837050D6202"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}