CVE-2017-11559: SQL Injection
An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-11559.
What is the affected software?
The affected software is ZOHO ManageEngine OpManager 12.2.
What is the severity of CVE-2017-11559?
The severity of CVE-2017-11559 is high, with a severity value of 7.5.
What is the description of CVE-2017-11559?
CVE-2017-11559 is a Blind SQL Injection vulnerability in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to the attack.
How can I fix CVE-2017-11559?
To fix CVE-2017-11559, it is recommended to update ZOHO ManageEngine OpManager to a version that is not affected by the vulnerability.