← Back

CVE-2022-36923

Published: Aug 10, 2022Modified: Sep 24, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

Affected (108)

7 products
Manageengine Firewall Analyzer
Manageengine Netflow Analyzer
Manageengine Opmanager
Manageengine Opmanager Msp
Manageengine Opmanager Plus
Manageengine Oputils
Configuration A
108 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Version 12.5 build125450
Version 12.5 build125451
Version 12.5 build125452
Version 12.5 build125453
Version 12.5 build125455
Version 12.5 build125456
Version 12.5 build125664
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126100
Version 12.6 build126101
Version 12.6 build126102
Version 12.6 build126103
Version 12.6 build126113
Version 12.6 build126114
Version 12.6 build126115
Version 12.6 build126116
Version 12.6 build126117
Zohocorp
Version 12.5 build125450
Version 12.5 build125451
Version 12.5 build125452
Version 12.5 build125453
Version 12.5 build125455
Version 12.5 build125456
Version 12.5 build125664
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126100
Version 12.6 build126101
Version 12.6 build126102
Version 12.6 build126103
Version 12.6 build126113
Version 12.6 build126114
Version 12.6 build126115
Version 12.6 build126116
Version 12.6 build126117
Zohocorp
Version 12.5 build125450
Version 12.5 build125451
Version 12.5 build125452
Version 12.5 build125453
Version 12.5 build125455
Version 12.5 build125456
Version 12.5 build125664
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126100
Version 12.6 build126101
Version 12.6 build126102
Version 12.6 build126103
Version 12.6 build126113
Version 12.6 build126114
Version 12.6 build126115
Version 12.6 build126116
Version 12.6 build126117
Zohocorp
Version 12.5 build125450
Version 12.5 build125451
Version 12.5 build125452
Version 12.5 build125453
Version 12.5 build125455
Version 12.5 build125456
Version 12.5 build125664
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126100
Version 12.6 build126101
Version 12.6 build126102
Version 12.6 build126103
Version 12.6 build126113
Version 12.6 build126114
Version 12.6 build126115
Version 12.6 build126116
Version 12.6 build126117
Zohocorp
Version 12.5 build125450
Version 12.5 build125656
Version 12.5 build125664
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126100
Version 12.6 build126103
Version 12.6 build126113
Version 12.6 build126117
Zohocorp
Version 12.5 build125450
Version 12.5 build125656
Version 12.5 build125664
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126100
Version 12.6 build126103
Version 12.6 build126113
Version 12.6 build126117
Zohocorp
Version 12.5 build125450
Version 12.5 build125451
Version 12.5 build125452
Version 12.5 build125453
Version 12.5 build125455
Version 12.5 build125456
Version 12.5 build125664
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126100
Version 12.6 build126101
Version 12.6 build126102
Version 12.6 build126103
Version 12.6 build126113
Version 12.6 build126114
Version 12.6 build126115
Version 12.6 build126116
Version 12.6 build126117

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.