7.5
CWE
306
Advisory Published
Updated

CVE-2020-11946

First published: Mon Apr 20 2020(Updated: )

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Zohocorp Manageengine Opmanager=12.5-build125000
Zohocorp Manageengine Opmanager=12.5-build125002
Zohocorp Manageengine Opmanager=12.5-build125100
Zohocorp Manageengine Opmanager=12.5-build125101
Zohocorp Manageengine Opmanager=12.5-build125102
Zohocorp Manageengine Opmanager=12.5-build125108
Zohocorp Manageengine Opmanager=12.5-build125110
Zohocorp Manageengine Opmanager=12.5-build125111
Zohocorp Manageengine Opmanager=12.5-build125112
Zohocorp Manageengine Opmanager=12.5-build125113
Zohocorp Manageengine Opmanager=12.5-build125114
Zohocorp Manageengine Opmanager=12.5-build125116
Zohocorp Manageengine Opmanager=12.5-build125117
Zohocorp Manageengine Opmanager=12.5-build125118

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2020-11946?

    CVE-2020-11946 is a vulnerability in Zoho ManageEngine OpManager before 125120 that allows an unauthenticated user to retrieve an API key via a servlet call.

  • What is the severity of CVE-2020-11946?

    The severity of CVE-2020-11946 is high with a CVSS score of 7.5.

  • How does CVE-2020-11946 affect Zoho ManageEngine OpManager?

    CVE-2020-11946 affects Zoho ManageEngine OpManager versions 12.5-build125000 to 12.5-build125118.

  • How can an unauthenticated user retrieve an API key in Zoho ManageEngine OpManager?

    An unauthenticated user can retrieve an API key in Zoho ManageEngine OpManager by making a servlet call.

  • How can I fix CVE-2020-11946 in Zoho ManageEngine OpManager?

    To fix CVE-2020-11946 in Zoho ManageEngine OpManager, update to version 12.5-build125120 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203