First published: Mon Aug 29 2022(Updated: )
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine NetFlow Analyzer | =12.5-build125450 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125451 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125452 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125453 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125455 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125456 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125459 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125464 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125467 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125469 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125471 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125476 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125482 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125483 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125484 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125485 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125488 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125490 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125557 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125566 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125568 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125582 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125584 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125585 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125606 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125615 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125647 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125656 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125657 | |
Zoho ManageEngine NetFlow Analyzer | =12.5-build125664 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126000 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126001 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126100 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126101 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126102 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126113 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126114 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126115 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126116 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126117 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126118 | |
Zoho ManageEngine NetFlow Analyzer | =12.6-build126119 | |
ManageEngine Network Configuration Manager | =12.5-build125450 | |
ManageEngine Network Configuration Manager | =12.5-build125451 | |
ManageEngine Network Configuration Manager | =12.5-build125452 | |
ManageEngine Network Configuration Manager | =12.5-build125453 | |
ManageEngine Network Configuration Manager | =12.5-build125455 | |
ManageEngine Network Configuration Manager | =12.5-build125456 | |
ManageEngine Network Configuration Manager | =12.5-build125459 | |
ManageEngine Network Configuration Manager | =12.5-build125465 | |
ManageEngine Network Configuration Manager | =12.5-build125469 | |
ManageEngine Network Configuration Manager | =12.5-build125471 | |
ManageEngine Network Configuration Manager | =12.5-build125475 | |
ManageEngine Network Configuration Manager | =12.5-build125482 | |
ManageEngine Network Configuration Manager | =12.5-build125483 | |
ManageEngine Network Configuration Manager | =12.5-build125485 | |
ManageEngine Network Configuration Manager | =12.5-build125488 | |
ManageEngine Network Configuration Manager | =12.5-build125490 | |
ManageEngine Network Configuration Manager | =12.5-build125565 | |
ManageEngine Network Configuration Manager | =12.5-build125568 | |
ManageEngine Network Configuration Manager | =12.5-build125583 | |
ManageEngine Network Configuration Manager | =12.5-build125584 | |
ManageEngine Network Configuration Manager | =12.5-build125598 | |
ManageEngine Network Configuration Manager | =12.5-build125612 | |
ManageEngine Network Configuration Manager | =12.5-build125615 | |
ManageEngine Network Configuration Manager | =12.5-build125617 | |
ManageEngine Network Configuration Manager | =12.5-build125646 | |
ManageEngine Network Configuration Manager | =12.5-build125650 | |
ManageEngine Network Configuration Manager | =12.5-build125656 | |
ManageEngine Network Configuration Manager | =12.5-build125657 | |
ManageEngine Network Configuration Manager | =12.5-build125664 | |
ManageEngine Network Configuration Manager | =12.6-build126000 | |
ManageEngine Network Configuration Manager | =12.6-build126001 | |
ManageEngine Network Configuration Manager | =12.6-build126002 | |
ManageEngine Network Configuration Manager | =12.6-build126100 | |
ManageEngine Network Configuration Manager | =12.6-build126101 | |
ManageEngine Network Configuration Manager | =12.6-build126102 | |
ManageEngine Network Configuration Manager | =12.6-build126103 | |
ManageEngine Network Configuration Manager | =12.6-build126104 | |
ManageEngine Network Configuration Manager | =12.6-build126113 | |
ManageEngine Network Configuration Manager | =12.6-build126114 | |
ManageEngine Network Configuration Manager | =12.6-build126115 | |
ManageEngine Network Configuration Manager | =12.6-build126116 | |
ManageEngine Network Configuration Manager | =12.6-build126117 | |
ManageEngine Network Configuration Manager | =12.6-build126118 | |
ManageEngine Network Configuration Manager | =12.6-build126119 | |
ManageEngine OpManager MSP | =12.5-build125450 | |
ManageEngine OpManager MSP | =12.5-build125451 | |
ManageEngine OpManager MSP | =12.5-build125452 | |
ManageEngine OpManager MSP | =12.5-build125453 | |
ManageEngine OpManager MSP | =12.5-build125455 | |
ManageEngine OpManager MSP | =12.5-build125456 | |
ManageEngine OpManager MSP | =12.5-build125457 | |
ManageEngine OpManager MSP | =12.5-build125466 | |
ManageEngine OpManager MSP | =12.5-build125467 | |
ManageEngine OpManager MSP | =12.5-build125468 | |
ManageEngine OpManager MSP | =12.5-build125469 | |
ManageEngine OpManager MSP | =12.5-build125470 | |
ManageEngine OpManager MSP | =12.5-build125476 | |
ManageEngine OpManager MSP | =12.5-build125482 | |
ManageEngine OpManager MSP | =12.5-build125483 | |
ManageEngine OpManager MSP | =12.5-build125485 | |
ManageEngine OpManager MSP | =12.5-build125486 | |
ManageEngine OpManager MSP | =12.5-build125487 | |
ManageEngine OpManager MSP | =12.5-build125488 | |
ManageEngine OpManager MSP | =12.5-build125489 | |
ManageEngine OpManager MSP | =12.5-build125567 | |
ManageEngine OpManager MSP | =12.5-build125568 | |
ManageEngine OpManager MSP | =12.5-build125587 | |
ManageEngine OpManager MSP | =12.5-build125588 | |
ManageEngine OpManager MSP | =12.5-build125589 | |
ManageEngine OpManager MSP | =12.5-build125597 | |
ManageEngine OpManager MSP | =12.5-build125598 | |
ManageEngine OpManager MSP | =12.5-build125599 | |
ManageEngine OpManager MSP | =12.5-build125601 | |
ManageEngine OpManager MSP | =12.5-build125603 | |
ManageEngine OpManager MSP | =12.5-build125604 | |
ManageEngine OpManager MSP | =12.5-build125605 | |
ManageEngine OpManager MSP | =12.5-build125611 | |
ManageEngine OpManager MSP | =12.5-build125612 | |
ManageEngine OpManager MSP | =12.5-build125613 | |
ManageEngine OpManager MSP | =12.5-build125614 | |
ManageEngine OpManager MSP | =12.5-build125615 | |
ManageEngine OpManager MSP | =12.5-build125616 | |
ManageEngine OpManager MSP | =12.5-build125617 | |
ManageEngine OpManager MSP | =12.5-build125628 | |
ManageEngine OpManager MSP | =12.5-build125629 | |
ManageEngine OpManager MSP | =12.5-build125630 | |
ManageEngine OpManager MSP | =12.5-build125631 | |
ManageEngine OpManager MSP | =12.5-build125632 | |
ManageEngine OpManager MSP | =12.5-build125634 | |
ManageEngine OpManager MSP | =12.5-build125635 | |
ManageEngine OpManager MSP | =12.5-build125638 | |
ManageEngine OpManager MSP | =12.5-build125639 | |
ManageEngine OpManager MSP | =12.5-build125645 | |
ManageEngine OpManager MSP | =12.5-build125648 | |
ManageEngine OpManager MSP | =12.5-build125649 | |
ManageEngine OpManager MSP | =12.5-build125651 | |
ManageEngine OpManager MSP | =12.5-build125652 | |
ManageEngine OpManager MSP | =12.5-build125653 | |
ManageEngine OpManager MSP | =12.5-build125654 | |
ManageEngine OpManager MSP | =12.5-build125655 | |
ManageEngine OpManager MSP | =12.5-build125656 | |
ManageEngine OpManager MSP | =12.5-build125657 | |
ManageEngine OpManager MSP | =12.5-build125664 | |
ManageEngine OpManager MSP | =12.6-build126000 | |
ManageEngine OpManager MSP | =12.6-build126001 | |
ManageEngine OpManager MSP | =12.6-build126002 | |
ManageEngine OpManager MSP | =12.6-build126100 | |
ManageEngine OpManager MSP | =12.6-build126101 | |
ManageEngine OpManager MSP | =12.6-build126102 | |
ManageEngine OpManager MSP | =12.6-build126103 | |
ManageEngine OpManager MSP | =12.6-build126104 | |
ManageEngine OpManager MSP | =12.6-build126113 | |
ManageEngine OpManager MSP | =12.6-build126114 | |
ManageEngine OpManager MSP | =12.6-build126115 | |
ManageEngine OpManager MSP | =12.6-build126116 | |
ManageEngine OpManager MSP | =12.6-build126117 | |
ManageEngine OpManager MSP | =12.6-build126118 | |
ManageEngine OpManager MSP | =12.6-build126119 | |
ManageEngine OpManager MSP | =12.5-build125450 | |
ManageEngine OpManager MSP | =12.5-build125656 | |
ManageEngine OpManager MSP | =12.5-build125657 | |
ManageEngine OpManager MSP | =12.5-build125664 | |
ManageEngine OpManager MSP | =12.6-build126000 | |
ManageEngine OpManager MSP | =12.6-build126001 | |
ManageEngine OpManager MSP | =12.6-build126002 | |
ManageEngine OpManager MSP | =12.6-build126100 | |
ManageEngine OpManager MSP | =12.6-build126103 | |
ManageEngine OpManager MSP | =12.6-build126104 | |
ManageEngine OpManager MSP | =12.6-build126113 | |
ManageEngine OpManager MSP | =12.6-build126117 | |
ManageEngine OpManager MSP | =12.6-build126119 | |
ManageEngine OpManager Plus | =12.5-build125450 | |
ManageEngine OpManager Plus | =12.5-build125656 | |
ManageEngine OpManager Plus | =12.5-build125657 | |
ManageEngine OpManager Plus | =12.5-build125664 | |
ManageEngine OpManager Plus | =12.6-build126000 | |
ManageEngine OpManager Plus | =12.6-build126001 | |
ManageEngine OpManager Plus | =12.6-build126002 | |
ManageEngine OpManager Plus | =12.6-build126100 | |
ManageEngine OpManager Plus | =12.6-build126103 | |
ManageEngine OpManager Plus | =12.6-build126104 | |
ManageEngine OpManager Plus | =12.6-build126113 | |
ManageEngine OpManager Plus | =12.6-build126117 | |
ManageEngine OpManager Plus | =12.6-build126119 | |
ManageEngine OpUtils | =12.5-build125450 | |
ManageEngine OpUtils | =12.5-build125451 | |
ManageEngine OpUtils | =12.5-build125452 | |
ManageEngine OpUtils | =12.5-build125453 | |
ManageEngine OpUtils | =12.5-build125455 | |
ManageEngine OpUtils | =12.5-build125456 | |
ManageEngine OpUtils | =12.5-build125657 | |
ManageEngine OpUtils | =12.5-build125664 | |
ManageEngine OpUtils | =12.6-build126000 | |
ManageEngine OpUtils | =12.6-build126001 | |
ManageEngine OpUtils | =12.6-build126002 | |
ManageEngine OpUtils | =12.6-build126100 | |
ManageEngine OpUtils | =12.6-build126101 | |
ManageEngine OpUtils | =12.6-build126102 | |
ManageEngine OpUtils | =12.6-build126103 | |
ManageEngine OpUtils | =12.6-build126104 | |
ManageEngine OpUtils | =12.6-build126113 | |
ManageEngine OpUtils | =12.6-build126114 | |
ManageEngine OpUtils | =12.6-build126115 | |
ManageEngine OpUtils | =12.6-build126116 | |
ManageEngine OpUtils | =12.6-build126117 | |
ManageEngine OpUtils | =12.6-build126119 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38772 has been rated as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2022-38772, update to the patched versions available: 125658, 126003, 126105, or 126120 for the affected software.
CVE-2022-38772 affects various ManageEngine products including OpManager, OpManager Plus, Network Configuration Manager, NetFlow Analyzer, and OpUtils.
CVE-2022-38772 is a vulnerability that allows authenticated users to make unauthorized database modifications leading to remote code execution.
Organizations using vulnerable builds of the affected ManageEngine products are at risk from CVE-2022-38772 if they have not applied the necessary updates.