CVE-2019-15106: Critical severity manageengine opmanager msp vulnerability
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-15106?
CVE-2019-15106 is a vulnerability in Zoho ManageEngine OpManager that allows an attacker to bypass the user password requirement and execute commands on the server.
How severe is CVE-2019-15106?
CVE-2019-15106 has a severity rating of 9.8, which is considered critical.
How can an attacker exploit CVE-2019-15106?
An attacker can exploit CVE-2019-15106 by using the 'username+'@opm' string as the password, bypassing the password requirement and executing commands on the server.
Which version of Zoho ManageEngine OpManager is affected by CVE-2019-15106?
Versions up to 12.4.034 of Zoho ManageEngine OpManager are affected by CVE-2019-15106.
Are there any patches or updates available for CVE-2019-15106?
Yes, patches and updates are available for CVE-2019-15106. Please refer to the official ManageEngine website for the latest security updates.