CWE
89
Advisory Published
Updated

CVE-2019-17602: SQL Injection

First published: Tue Oct 15 2019(Updated: )

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
ManageEngine OpManager MSP<12.4
ManageEngine OpManager MSP=12.4
ManageEngine OpManager MSP=12.4-build124000
ManageEngine OpManager MSP=12.4-build124011
ManageEngine OpManager MSP=12.4-build124012
ManageEngine OpManager MSP=12.4-build124013
ManageEngine OpManager MSP=12.4-build124014
ManageEngine OpManager MSP=12.4-build124015
ManageEngine OpManager MSP=12.4-build124016
ManageEngine OpManager MSP=12.4-build124022
ManageEngine OpManager MSP=12.4-build124023
ManageEngine OpManager MSP=12.4-build124024
ManageEngine OpManager MSP=12.4-build124025
ManageEngine OpManager MSP=12.4-build124026
ManageEngine OpManager MSP=12.4-build124027
ManageEngine OpManager MSP=12.4-build124030
ManageEngine OpManager MSP=12.4-build124033
ManageEngine OpManager MSP=12.4-build124037
ManageEngine OpManager MSP=12.4-build124039
ManageEngine OpManager MSP=12.4-build124040
ManageEngine OpManager MSP=12.4-build124041
ManageEngine OpManager MSP=12.4-build124042
ManageEngine OpManager MSP=12.4-build124043
ManageEngine OpManager MSP=12.4-build124051
ManageEngine OpManager MSP=12.4-build124053
ManageEngine OpManager MSP=12.4-build124054
ManageEngine OpManager MSP=12.4-build124056
ManageEngine OpManager MSP=12.4-build124058
ManageEngine OpManager MSP=12.4-build124065
ManageEngine OpManager MSP=12.4-build124066
ManageEngine OpManager MSP=12.4-build124067
ManageEngine OpManager MSP=12.4-build124069
ManageEngine OpManager MSP=12.4-build124070
ManageEngine OpManager MSP=12.4-build124071
ManageEngine OpManager MSP=12.4-build124074
ManageEngine OpManager MSP=12.4-build124075
ManageEngine OpManager MSP=12.4-build124081
ManageEngine OpManager MSP=12.4-build124082
ManageEngine OpManager MSP=12.4-build124085
ManageEngine OpManager MSP=12.4-build124086
ManageEngine OpManager MSP=12.4-build124087

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2019-17602?

    The severity of CVE-2019-17602 is critical with a severity value of 9.8.

  • How does CVE-2019-17602 affect Zoho ManageEngine OpManager?

    CVE-2019-17602 affects Zoho ManageEngine OpManager versions before 12.4 build 124089 and can be exploited through SQL injection.

  • Is authentication required to exploit CVE-2019-17602?

    Depending on the configuration, CVE-2019-17602 can be exploited both unauthenticated and authenticated.

  • How do I fix CVE-2019-17602?

    To fix CVE-2019-17602, upgrade Zoho ManageEngine OpManager to version 12.4 build 124089 or later.

  • Where can I find more information about CVE-2019-17602?

    More information about CVE-2019-17602 can be found at the following link: [https://www.manageengine.com/network-monitoring/help/read-me-complete.html](https://www.manageengine.com/network-monitoring/help/read-me-complete.html)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203