← Back

CVE-2022-43473

nvd nist
Published: Mar 30, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

Affected (81)

3 products
Manageengine Opmanager
Manageengine Opmanager Plus
Manageengine Opmanager Msp
Configuration A
47 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 12.6
Version 12.6 build126000
Version 12.6 build126001
Version 12.6 build126002
Version 12.6 build126004
Version 12.6 build126005
Version 12.6 build126100
Version 12.6 build126101
Version 12.6 build126102
Version 12.6 build126103
Version 12.6 build126104
Version 12.6 build126107
Version 12.6 build126108
Version 12.6 build126109
Version 12.6 build126110
Version 12.6 build126113
Version 12.6 build126114
Version 12.6 build126115
Version 12.6 build126116
Version 12.6 build126117
Version 12.6 build126118
Version 12.6 build126119
Version 12.6 build126120
Version 12.6 build126121
Version 12.6 build126122
Version 12.6 build126130
Version 12.6 build126131
Version 12.6 build126132
Version 12.6 build126134
Version 12.6 build126135
Version 12.6 build126136
Version 12.6 build126139
Version 12.6 build126141
Version 12.6 build126147
Version 12.6 build126148
Version 12.6 build126149
Version 12.6 build126150
Version 12.6 build126151
Version 12.6 build126154
Version 12.6 build126155
Version 12.6 build126162
Version 12.6 build126163
Version 12.6 build126164
Version 12.6 build126165
Version 12.6 build126166
Version 12.6 build126167
Version 12.6 build126168
Configuration B
17 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 12.6
Version 12.6 build126001
Version 12.6 build126002
Version 12.6 build126100
Version 12.6 build126103
Version 12.6 build126104
Version 12.6 build126107
Version 12.6 build126113
Version 12.6 build126117
Version 12.6 build126119
Version 12.6 build126122
Version 12.6 build126139
Version 12.6 build126140
Version 12.6 build126141
Version 12.6 build126154
Version 12.6 build126155
Version 12.6 build126264
Configuration C
17 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 12.6
Version 12.6 build126001
Version 12.6 build126002
Version 12.6 build126100
Version 12.6 build126103
Version 12.6 build126104
Version 12.6 build126107
Version 12.6 build126113
Version 12.6 build126117
Version 12.6 build126119
Version 12.6 build126122
Version 12.6 build126139
Version 12.6 build126140
Version 12.6 build126141
Version 12.6 build126154
Version 12.6 build126155
Version 12.6 build126264

References (5)

Source: talos-cna@cisco.com
ExploitThird Party Advisory
Source: talos-cna@cisco.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.