CVE-2019-17602: SQL Injection
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17602?
The severity of CVE-2019-17602 is critical with a severity value of 9.8.
How does CVE-2019-17602 affect Zoho ManageEngine OpManager?
CVE-2019-17602 affects Zoho ManageEngine OpManager versions before 12.4 build 124089 and can be exploited through SQL injection.
Is authentication required to exploit CVE-2019-17602?
Depending on the configuration, CVE-2019-17602 can be exploited both unauthenticated and authenticated.
How do I fix CVE-2019-17602?
To fix CVE-2019-17602, upgrade Zoho ManageEngine OpManager to version 12.4 build 124089 or later.
Where can I find more information about CVE-2019-17602?
More information about CVE-2019-17602 can be found at the following link: [https://www.manageengine.com/network-monitoring/help/read-me-complete.html](https://www.manageengine.com/network-monitoring/help/read-me-complete.html)