First published: Wed Aug 10 2022(Updated: )
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Firewall Analyzer | =12.5-build125450 | |
ManageEngine Firewall Analyzer | =12.5-build125451 | |
ManageEngine Firewall Analyzer | =12.5-build125452 | |
ManageEngine Firewall Analyzer | =12.5-build125453 | |
ManageEngine Firewall Analyzer | =12.5-build125455 | |
ManageEngine Firewall Analyzer | =12.5-build125456 | |
ManageEngine Firewall Analyzer | =12.5-build125664 | |
ManageEngine Firewall Analyzer | =12.6-build126000 | |
ManageEngine Firewall Analyzer | =12.6-build126001 | |
ManageEngine Firewall Analyzer | =12.6-build126100 | |
ManageEngine Firewall Analyzer | =12.6-build126101 | |
ManageEngine Firewall Analyzer | =12.6-build126102 | |
ManageEngine Firewall Analyzer | =12.6-build126103 | |
ManageEngine Firewall Analyzer | =12.6-build126113 | |
ManageEngine Firewall Analyzer | =12.6-build126114 | |
ManageEngine Firewall Analyzer | =12.6-build126115 | |
ManageEngine Firewall Analyzer | =12.6-build126116 | |
ManageEngine Firewall Analyzer | =12.6-build126117 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125450 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125451 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125452 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125453 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125455 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125456 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125664 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126000 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126001 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126100 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126101 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126102 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126103 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126113 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126114 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126115 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126116 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126117 | |
ManageEngine Network Configuration Manager | =12.5-build125450 | |
ManageEngine Network Configuration Manager | =12.5-build125451 | |
ManageEngine Network Configuration Manager | =12.5-build125452 | |
ManageEngine Network Configuration Manager | =12.5-build125453 | |
ManageEngine Network Configuration Manager | =12.5-build125455 | |
ManageEngine Network Configuration Manager | =12.5-build125456 | |
ManageEngine Network Configuration Manager | =12.5-build125664 | |
ManageEngine Network Configuration Manager | =12.6-build126000 | |
ManageEngine Network Configuration Manager | =12.6-build126001 | |
ManageEngine Network Configuration Manager | =12.6-build126100 | |
ManageEngine Network Configuration Manager | =12.6-build126101 | |
ManageEngine Network Configuration Manager | =12.6-build126102 | |
ManageEngine Network Configuration Manager | =12.6-build126103 | |
ManageEngine Network Configuration Manager | =12.6-build126113 | |
ManageEngine Network Configuration Manager | =12.6-build126114 | |
ManageEngine Network Configuration Manager | =12.6-build126115 | |
ManageEngine Network Configuration Manager | =12.6-build126116 | |
ManageEngine Network Configuration Manager | =12.6-build126117 | |
ManageEngine OpManager MSP | =12.5-build125450 | |
ManageEngine OpManager MSP | =12.5-build125451 | |
ManageEngine OpManager MSP | =12.5-build125452 | |
ManageEngine OpManager MSP | =12.5-build125453 | |
ManageEngine OpManager MSP | =12.5-build125455 | |
ManageEngine OpManager MSP | =12.5-build125456 | |
ManageEngine OpManager MSP | =12.5-build125664 | |
ManageEngine OpManager MSP | =12.6-build126000 | |
ManageEngine OpManager MSP | =12.6-build126001 | |
ManageEngine OpManager MSP | =12.6-build126100 | |
ManageEngine OpManager MSP | =12.6-build126101 | |
ManageEngine OpManager MSP | =12.6-build126102 | |
ManageEngine OpManager MSP | =12.6-build126103 | |
ManageEngine OpManager MSP | =12.6-build126113 | |
ManageEngine OpManager MSP | =12.6-build126114 | |
ManageEngine OpManager MSP | =12.6-build126115 | |
ManageEngine OpManager MSP | =12.6-build126116 | |
ManageEngine OpManager MSP | =12.6-build126117 | |
ManageEngine OpManager MSP | =12.5-build125450 | |
ManageEngine OpManager MSP | =12.5-build125656 | |
ManageEngine OpManager MSP | =12.5-build125664 | |
ManageEngine OpManager MSP | =12.6-build126000 | |
ManageEngine OpManager MSP | =12.6-build126001 | |
ManageEngine OpManager MSP | =12.6-build126100 | |
ManageEngine OpManager MSP | =12.6-build126103 | |
ManageEngine OpManager MSP | =12.6-build126113 | |
ManageEngine OpManager MSP | =12.6-build126117 | |
ManageEngine OpManager Plus | =12.5-build125450 | |
ManageEngine OpManager Plus | =12.5-build125656 | |
ManageEngine OpManager Plus | =12.5-build125664 | |
ManageEngine OpManager Plus | =12.6-build126000 | |
ManageEngine OpManager Plus | =12.6-build126001 | |
ManageEngine OpManager Plus | =12.6-build126100 | |
ManageEngine OpManager Plus | =12.6-build126103 | |
ManageEngine OpManager Plus | =12.6-build126113 | |
ManageEngine OpManager Plus | =12.6-build126117 | |
ManageEngine OpUtils | =12.5-build125450 | |
ManageEngine OpUtils | =12.5-build125451 | |
ManageEngine OpUtils | =12.5-build125452 | |
ManageEngine OpUtils | =12.5-build125453 | |
ManageEngine OpUtils | =12.5-build125455 | |
ManageEngine OpUtils | =12.5-build125456 | |
ManageEngine OpUtils | =12.5-build125664 | |
ManageEngine OpUtils | =12.6-build126000 | |
ManageEngine OpUtils | =12.6-build126001 | |
ManageEngine OpUtils | =12.6-build126100 | |
ManageEngine OpUtils | =12.6-build126101 | |
ManageEngine OpUtils | =12.6-build126102 | |
ManageEngine OpUtils | =12.6-build126103 | |
ManageEngine OpUtils | =12.6-build126113 | |
ManageEngine OpUtils | =12.6-build126114 | |
ManageEngine OpUtils | =12.6-build126115 | |
ManageEngine OpUtils | =12.6-build126116 | |
ManageEngine OpUtils | =12.6-build126117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36923 is classified as a critical vulnerability due to its potential to allow unauthorized access to API keys.
To remediate CVE-2022-36923, update your Zoho ManageEngine products to the latest versions released on or after July 27, 2022.
CVE-2022-36923 affects ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils.
CVE-2022-36923 can lead to unauthorized access to sensitive data through API key exposure, posing risks to data integrity and confidentiality.
If vulnerable, immediately apply the necessary updates to your affected ManageEngine products to prevent exploitation.