Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
References
Link | Resource |
---|---|
https://www.manageengine.com/itom/advisory/cve-2022-36923.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Aug 2022, 16:01
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CWE | CWE-755 | |
CPE | cpe:2.3:a:zohocorp:manageengine_oputils:12.5:build125664:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5:build125664:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5:build125452:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126102:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126102:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126103:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126103:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5:build125456:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126113:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126115:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126102:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.6:build126000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126101:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126100:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5:build125453:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.5:build125450:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125456:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125455:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126102:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5:build125450:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.5:build125450:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5:build125451:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126113:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126102:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126114:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126103:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126101:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126101:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.6:build126117:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.5:build125455:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126117:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126117:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.5:build125664:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.6:build126001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5:build125456:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126115:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126113:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5:build125450:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.5:build125664:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125452:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.6:build126103:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126115:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.6:build126113:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126100:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.6:build126117:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125450:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126101:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5:build125451:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125664:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126114:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126116:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126103:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.5:build125656:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126115:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.6:build126001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.6:build126000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126114:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126113:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.5:build125453:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.5:build125656:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125451:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125453:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.5:build125451:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126115:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.6:build126100:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126117:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.5:build125452:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5:build125455:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126116:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5:build125664:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.5:build125664:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5:build125452:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126113:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.6:build126100:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.5:build125451:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.5:build125456:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126114:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126000:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.6:build126103:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126117:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.5:build125450:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126116:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5:build125453:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126100:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.5:build125450:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.5:build125453:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126116:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126100:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.5:build125452:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.5:build125456:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126100:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5:build125455:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126001:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager:12.6:build126116:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6:build126114:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_firewall_analyzer:12.6:build126103:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.6:build126113:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6:build126117:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.5:build125455:*:*:*:*:*:* cpe:2.3:a:zohocorp:manageengine_oputils:12.6:build126101:*:*:*:*:*:* |
|
References | (MISC) https://www.manageengine.com/itom/advisory/cve-2022-36923.html - Vendor Advisory |
10 Aug 2022, 20:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-10 20:16
Updated : 2024-02-04 22:51
NVD link : CVE-2022-36923
Mitre link : CVE-2022-36923
CVE.ORG link : CVE-2022-36923
JSON object : View
Products Affected
zohocorp
- manageengine_opmanager_plus
- manageengine_oputils
- manageengine_opmanager_msp
- manageengine_network_configuration_manager
- manageengine_firewall_analyzer
- manageengine_netflow_analyzer
- manageengine_opmanager
CWE
CWE-755
Improper Handling of Exceptional Conditions