CVE-2018-17283: SQL Injection
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17283?
CVE-2018-17283 is a vulnerability in Zoho ManageEngine OpManager before 12.3 Build 123196 that allows unauthorized access to certain API requests.
How severe is CVE-2018-17283?
CVE-2018-17283 has a severity score of 7.5 out of 10, which is considered high.
How can I exploit CVE-2018-17283?
To exploit CVE-2018-17283, an attacker can use a specially crafted request to gain unauthorized access or conduct SQL injections on the affected system.
Is there a fix for CVE-2018-17283?
Yes, updating Zoho ManageEngine OpManager to version 12.3 Build 123196 or later resolves CVE-2018-17283.
Where can I find more information about CVE-2018-17283?
You can find more information about CVE-2018-17283 at the following references: [Reference 1](https://github.com/x-f1v3/ForCve/issues/4) and [Reference 2](https://www.manageengine.com/network-monitoring/help/read-me.html).