CVE-2019-17602
Status: ModifiedCritical (9.8)—
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 81%
- Percentile among all scored CVEs: 100
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-89
References
Raw JSON (NVD)
Show
{
"id": "CVE-2019-17602",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-10-15T21:15:11.127",
"references": [
{
"url": "https://www.manageengine.com/network-monitoring/help/read-me-complete.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.manageengine.com/network-monitoring/help/read-me-complete.html",
"tags": [
"Release Notes",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated."
},
{
"lang": "es",
"value": "Se detectó un problema en Zoho ManageEngine OpManager versiones anteriores a 12.4 build 124089. El servlet OPMDeviceDetailsServlet es propenso a la inyección SQL. Dependiendo de la configuración, esta vulnerabilidad podría ser explotada no autenticado o autenticado."
}
],
"lastModified": "2026-06-17T02:24:15.737",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC6C8B88-B295-48DB-859A-7AF8E9027F62",
"versionEndExcluding": "12.4"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B666DF1F-0EF8-41F0-9EA0-EB104F87405F"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124000:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B7042C9-FD7C-4A83-A755-1429D3CEF91D"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124011:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "86F61865-FB7B-4F12-B8EF-81A1DFB5E7E9"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124012:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D81E915-18CC-4419-879D-A2D90472F526"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124013:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B9314BA-7CA4-46C2-9ADD-AA15101081FB"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124014:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A94FB0E-7487-4E18-A7AD-19E47B03BF1C"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124015:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D99A8A01-8EDC-4AE6-8ED9-C7AF12DEDA62"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124016:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44A9BF34-7B3B-4B5F-AEFD-AA7434C6A682"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124022:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33068139-B994-4145-B73A-2344A699A0A0"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124023:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B798718E-3E01-4F3D-AD43-9BA7939E2EE0"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124024:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E0C42019-0D5A-4938-87AB-F787C55E9834"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124025:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "373AA6C3-DA45-4CCD-88EF-859858732FDB"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124026:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13E24695-F223-4F62-B344-4CCB0BBE1050"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124027:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8EDB65B-34E1-4F89-B2E0-CEE13F39DA90"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124030:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8F7F90C-57BB-4E2F-BD79-1F56375A4E73"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124033:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1343F39-5FAA-4EB7-B95A-5D5133AD5717"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124037:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C23F2AB2-714D-4548-B9F9-315CE31CF573"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124039:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC8CDE36-EC3C-4F61-872C-8DD33688E0E3"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124040:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D790A131-CA15-42A1-8F35-3DCF27D51060"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124041:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C91F973F-3910-41E6-9D2F-3506E8EF5A0A"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124042:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "471FFC26-5DE7-42C6-B30B-EF5D1E1A35C2"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124043:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5407B79-C1DF-481E-83A3-BCE36BEE29E3"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124051:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F09EF7FD-47EB-4989-8805-74EC075F91AD"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124053:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F91FCCC4-C8C0-49B2-86C7-B2896D72F019"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124054:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F7679A19-1874-4E97-87A5-60903A549A26"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124056:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D3B991A7-452F-46C6-AB37-78137A7B27CA"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124058:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "66A7CEE9-8647-462A-8F50-9159132E01FC"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124065:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28D368E2-FBB1-4DC2-BDBF-7A4F994A14F8"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124066:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9F3220A-D461-4412-9F73-B74EB299DBA1"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124067:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7442E3D2-83CC-4F75-89E3-64BAE5937722"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124069:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07B87F17-6AF0-4545-9527-154E0C6483C7"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124070:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B565B110-9A53-4BA1-BAB9-C6C16DEECD2F"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124071:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA46F3B7-0650-4630-9005-1FAC1EC22EE0"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124074:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8706C9CD-0D79-4661-B0C5-AB1813DE1F0F"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124075:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BACB527-2F9E-4C6B-8C7B-696EAD5251FC"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124081:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC9D8F85-EFB8-4D0E-BD8F-6DBE239559F0"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124082:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0297A0EA-43F2-4AD0-BC73-E6014F1F74BD"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124085:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA5F1F18-247B-4081-8B53-E34B1512D47F"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124086:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2B8F85FF-78A7-4BF4-83C2-FC3ABFBC8715"
},
{
"criteria": "cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124087:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C1A1836-D054-4B96-890E-E837050D6202"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}