Zohocorp Manageengine Opmanager vulnerabilities

56 known vulnerabilities affecting zohocorp/manageengine_opmanager.

Total CVEs
56
CISA KEV
0
Public exploits
16
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH23MEDIUM14

Vulnerabilities

Page 1 of 3
CVE-2025-9226MEDIUMCVSS 4.6fixed in 1285822026-01-30
CVE-2025-9226 [MEDIUM] CWE-79 CVE-2025-9226: Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected Zohocorp ManageEngine OpManager, NetFlow Analyzer, and OpUtils versions prior to 128582 are affected by a stored cross-site scripting vulnerability in the Subnet Details.
cvelistv5nvd
CVE-2025-9227MEDIUMCVSS 6.5≤ 1286092025-11-11
CVE-2025-9227 [MEDIUM] CWE-79 CVE-2025-9227: Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
cvelistv5nvd
CVE-2024-5466HIGHCVSS 8.8≤ 12.7v12.82024-08-23
CVE-2024-5466 [HIGH] CWE-94 CVE-2024-5466: Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are v Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
nvd
CVE-2023-47211HIGHCVSS 8.6PoCfixed in 12.7v12.72024-01-08
CVE-2023-47211 [CRITICAL] CWE-22 CVE-2023-47211: A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
nvd
CVE-2023-6105MEDIUMCVSS 5.5fixed in 12.5v12.5+2 more2023-11-15
CVE-2023-6105 [MEDIUM] CWE-200 CVE-2023-6105: An information disclosure vulnerability exists in multiple ManageEngine products that can result in An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine pr
nvd
CVE-2023-31099HIGHCVSS 8.8fixed in 12.6v12.62023-05-04
CVE-2023-31099 [HIGH] CVE-2023-31099: Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execu Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
nvd
CVE-2022-43473MEDIUMCVSS 5.4fixed in 12.6v12.62023-03-30
CVE-2022-43473 [MEDIUM] CWE-611 CVE-2022-43473: A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of Manage A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
nvd
CVE-2022-38772HIGHCVSS 8.8v12.5v12.62022-08-29
CVE-2022-38772 [HIGH] CVE-2022-38772: Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow A Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
nvd
CVE-2022-37024HIGHCVSS 8.8v12.5v12.62022-08-10
CVE-2022-37024 [HIGH] CVE-2022-37024: Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow A Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.
nvd
CVE-2022-36923HIGHCVSS 7.5PoCv12.5v12.62022-08-10
CVE-2022-36923 [HIGH] CWE-755 CVE-2022-36923: Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow A Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
nvd
CVE-2022-35404HIGHCVSS 8.2fixed in 12.5v12.52022-07-18
CVE-2022-35404 [HIGH] CWE-20 CVE-2022-35404: ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to u ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
nvd
CVE-2022-29535CRITICALCVSS 9.8fixed in 12.5v12.52022-05-05
CVE-2022-29535 [CRITICAL] CWE-89 CVE-2022-29535: Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
nvd
CVE-2022-27908HIGHCVSS 8.8fixed in 12.5v12.52022-04-18
CVE-2022-27908 [HIGH] CWE-89 CVE-2022-27908: Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Inj Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.
nvd
CVE-2021-44514CRITICALCVSS 9.8v12.52021-12-09
CVE-2021-44514 [CRITICAL] CWE-287 CVE-2021-44514: OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
nvd
CVE-2021-40493CRITICALCVSS 9.8fixed in 12.5v12.52021-10-13
CVE-2021-40493 [CRITICAL] CWE-89 CVE-2021-40493: Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
nvd
CVE-2021-41075CRITICALCVSS 9.8fixed in 12.5v12.52021-10-13
CVE-2021-41075 [CRITICAL] CWE-89 CVE-2021-41075: The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in t The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
nvd
CVE-2021-41288CRITICALCVSS 9.8≤ 12.4v12.52021-09-30
CVE-2021-41288 [CRITICAL] CWE-89 CVE-2021-41288: Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReport Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
nvd
CVE-2021-3287CRITICALCVSS 9.8PoCfixed in 12.5v12.52021-04-22
CVE-2021-3287 [CRITICAL] CWE-502 CVE-2021-3287: Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a ge Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
nvd
CVE-2021-20078CRITICALCVSS 9.1fixed in 12.5v12.52021-04-01
CVE-2021-20078 [CRITICAL] CWE-22 CVE-2021-20078: Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerabili Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.
nvd
CVE-2020-28653CRITICALCVSS 9.8PoCfixed in 12.5v12.52021-02-03
CVE-2020-28653 [CRITICAL] CVE-2020-28653: Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Rem Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
nvd