First published: Thu Mar 30 2023(Updated: )
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager MSP | <12.6 | |
ManageEngine OpManager MSP | =12.6-build126000 | |
ManageEngine OpManager MSP | =12.6-build126001 | |
ManageEngine OpManager MSP | =12.6-build126002 | |
ManageEngine OpManager MSP | =12.6-build126004 | |
ManageEngine OpManager MSP | =12.6-build126005 | |
ManageEngine OpManager MSP | =12.6-build126100 | |
ManageEngine OpManager MSP | =12.6-build126101 | |
ManageEngine OpManager MSP | =12.6-build126102 | |
ManageEngine OpManager MSP | =12.6-build126103 | |
ManageEngine OpManager MSP | =12.6-build126104 | |
ManageEngine OpManager MSP | =12.6-build126107 | |
ManageEngine OpManager MSP | =12.6-build126108 | |
ManageEngine OpManager MSP | =12.6-build126109 | |
ManageEngine OpManager MSP | =12.6-build126110 | |
ManageEngine OpManager MSP | =12.6-build126113 | |
ManageEngine OpManager MSP | =12.6-build126114 | |
ManageEngine OpManager MSP | =12.6-build126115 | |
ManageEngine OpManager MSP | =12.6-build126116 | |
ManageEngine OpManager MSP | =12.6-build126117 | |
ManageEngine OpManager MSP | =12.6-build126118 | |
ManageEngine OpManager MSP | =12.6-build126119 | |
ManageEngine OpManager MSP | =12.6-build126120 | |
ManageEngine OpManager MSP | =12.6-build126121 | |
ManageEngine OpManager MSP | =12.6-build126122 | |
ManageEngine OpManager MSP | =12.6-build126130 | |
ManageEngine OpManager MSP | =12.6-build126131 | |
ManageEngine OpManager MSP | =12.6-build126132 | |
ManageEngine OpManager MSP | =12.6-build126134 | |
ManageEngine OpManager MSP | =12.6-build126135 | |
ManageEngine OpManager MSP | =12.6-build126136 | |
ManageEngine OpManager MSP | =12.6-build126139 | |
ManageEngine OpManager MSP | =12.6-build126141 | |
ManageEngine OpManager MSP | =12.6-build126147 | |
ManageEngine OpManager MSP | =12.6-build126148 | |
ManageEngine OpManager MSP | =12.6-build126149 | |
ManageEngine OpManager MSP | =12.6-build126150 | |
ManageEngine OpManager MSP | =12.6-build126151 | |
ManageEngine OpManager MSP | =12.6-build126154 | |
ManageEngine OpManager MSP | =12.6-build126155 | |
ManageEngine OpManager MSP | =12.6-build126162 | |
ManageEngine OpManager MSP | =12.6-build126163 | |
ManageEngine OpManager MSP | =12.6-build126164 | |
ManageEngine OpManager MSP | =12.6-build126165 | |
ManageEngine OpManager MSP | =12.6-build126166 | |
ManageEngine OpManager MSP | =12.6-build126167 | |
ManageEngine OpManager MSP | =12.6-build126168 | |
ManageEngine OpManager Plus | <12.6 | |
ManageEngine OpManager Plus | =12.6-build126001 | |
ManageEngine OpManager Plus | =12.6-build126002 | |
ManageEngine OpManager Plus | =12.6-build126100 | |
ManageEngine OpManager Plus | =12.6-build126103 | |
ManageEngine OpManager Plus | =12.6-build126104 | |
ManageEngine OpManager Plus | =12.6-build126107 | |
ManageEngine OpManager Plus | =12.6-build126113 | |
ManageEngine OpManager Plus | =12.6-build126117 | |
ManageEngine OpManager Plus | =12.6-build126119 | |
ManageEngine OpManager Plus | =12.6-build126122 | |
ManageEngine OpManager Plus | =12.6-build126139 | |
ManageEngine OpManager Plus | =12.6-build126140 | |
ManageEngine OpManager Plus | =12.6-build126141 | |
ManageEngine OpManager Plus | =12.6-build126154 | |
ManageEngine OpManager Plus | =12.6-build126155 | |
ManageEngine OpManager Plus | =12.6-build126264 | |
ManageEngine OpManager MSP | <12.6 | |
ManageEngine OpManager MSP | =12.6-build126001 | |
ManageEngine OpManager MSP | =12.6-build126002 | |
ManageEngine OpManager MSP | =12.6-build126100 | |
ManageEngine OpManager MSP | =12.6-build126103 | |
ManageEngine OpManager MSP | =12.6-build126104 | |
ManageEngine OpManager MSP | =12.6-build126107 | |
ManageEngine OpManager MSP | =12.6-build126113 | |
ManageEngine OpManager MSP | =12.6-build126117 | |
ManageEngine OpManager MSP | =12.6-build126119 | |
ManageEngine OpManager MSP | =12.6-build126122 | |
ManageEngine OpManager MSP | =12.6-build126139 | |
ManageEngine OpManager MSP | =12.6-build126140 | |
ManageEngine OpManager MSP | =12.6-build126141 | |
ManageEngine OpManager MSP | =12.6-build126154 | |
ManageEngine OpManager MSP | =12.6-build126155 | |
ManageEngine OpManager MSP | =12.6-build126264 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43473 is classified as a medium severity vulnerability due to its potential for blind XML External Entity (XXE) exploitation.
To mitigate CVE-2022-43473, users should update ManageEngine OpManager to version 12.6 or later that contains the necessary security patches.
CVE-2022-43473 can be exploited to perform Server-Side Request Forgery (SSRF) attacks by crafting malicious XML payloads.
CVE-2022-43473 impacts ManageEngine OpManager versions prior to 12.6, including various builds of 12.6.
Yes, CVE-2022-43473 is considered easy to exploit, making it critical for organizations using the affected software to address the vulnerability promptly.