CVE-2015-7765: Critical severity ZohoCorp ManageEngine OpManager vulnerability
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7765?
CVE-2015-7765 is rated as a high severity vulnerability due to the potential for unauthorized administrative access.
How do I fix CVE-2015-7765?
To fix CVE-2015-7765, change the hardcoded password for the IntegrationUser account from 'plugin' to a stronger password.
Who is affected by CVE-2015-7765?
Users of ZOHO ManageEngine OpManager versions 11.5 build 11600 and earlier are affected by CVE-2015-7765.
What type of vulnerability is CVE-2015-7765?
CVE-2015-7765 is a security vulnerability that involves hardcoded credentials allowing unauthorized access.
Can CVE-2015-7765 lead to remote code execution?
Yes, CVE-2015-7765 can potentially lead to remote code execution by allowing authenticated users to gain administrator access.