First published: Fri Oct 09 2015(Updated: )
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager MSP | =11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7765 is rated as a high severity vulnerability due to the potential for unauthorized administrative access.
To fix CVE-2015-7765, change the hardcoded password for the IntegrationUser account from 'plugin' to a stronger password.
Users of ZOHO ManageEngine OpManager versions 11.5 build 11600 and earlier are affected by CVE-2015-7765.
CVE-2015-7765 is a security vulnerability that involves hardcoded credentials allowing unauthorized access.
Yes, CVE-2015-7765 can potentially lead to remote code execution by allowing authenticated users to gain administrator access.