CVE-2015-7766: Critical severity manageengine opmanager msp vulnerability
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT//INTO."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7766?
CVE-2015-7766 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2015-7766?
To fix CVE-2015-7766, upgrade ManageEngine OpManager to the latest version that addresses this vulnerability.
What versions of ManageEngine OpManager are affected by CVE-2015-7766?
ManageEngine OpManager versions 11.5 and earlier, as well as version 11.6, are affected by CVE-2015-7766.
What type of attack is possible with CVE-2015-7766?
CVE-2015-7766 allows an attacker to bypass SQL query restrictions, enabling potential remote code execution.
Who can be impacted by CVE-2015-7766?
Remote administrators of ManageEngine OpManager can be impacted by CVE-2015-7766 if they do not apply the necessary patches.