First published: Thu Mar 30 2023(Updated: )
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine OpManager | <12.6 | |
Zohocorp ManageEngine OpManager | =12.6-build126000 | |
Zohocorp ManageEngine OpManager | =12.6-build126001 | |
Zohocorp ManageEngine OpManager | =12.6-build126002 | |
Zohocorp ManageEngine OpManager | =12.6-build126004 | |
Zohocorp ManageEngine OpManager | =12.6-build126005 | |
Zohocorp ManageEngine OpManager | =12.6-build126100 | |
Zohocorp ManageEngine OpManager | =12.6-build126101 | |
Zohocorp ManageEngine OpManager | =12.6-build126102 | |
Zohocorp ManageEngine OpManager | =12.6-build126103 | |
Zohocorp ManageEngine OpManager | =12.6-build126104 | |
Zohocorp ManageEngine OpManager | =12.6-build126107 | |
Zohocorp ManageEngine OpManager | =12.6-build126108 | |
Zohocorp ManageEngine OpManager | =12.6-build126109 | |
Zohocorp ManageEngine OpManager | =12.6-build126110 | |
Zohocorp ManageEngine OpManager | =12.6-build126113 | |
Zohocorp ManageEngine OpManager | =12.6-build126114 | |
Zohocorp ManageEngine OpManager | =12.6-build126115 | |
Zohocorp ManageEngine OpManager | =12.6-build126116 | |
Zohocorp ManageEngine OpManager | =12.6-build126117 | |
Zohocorp ManageEngine OpManager | =12.6-build126118 | |
Zohocorp ManageEngine OpManager | =12.6-build126119 | |
Zohocorp ManageEngine OpManager | =12.6-build126120 | |
Zohocorp ManageEngine OpManager | =12.6-build126121 | |
Zohocorp ManageEngine OpManager | =12.6-build126122 | |
Zohocorp ManageEngine OpManager | =12.6-build126130 | |
Zohocorp ManageEngine OpManager | =12.6-build126131 | |
Zohocorp ManageEngine OpManager | =12.6-build126132 | |
Zohocorp ManageEngine OpManager | =12.6-build126134 | |
Zohocorp ManageEngine OpManager | =12.6-build126135 | |
Zohocorp ManageEngine OpManager | =12.6-build126136 | |
Zohocorp ManageEngine OpManager | =12.6-build126139 | |
Zohocorp ManageEngine OpManager | =12.6-build126141 | |
Zohocorp ManageEngine OpManager | =12.6-build126147 | |
Zohocorp ManageEngine OpManager | =12.6-build126148 | |
Zohocorp ManageEngine OpManager | =12.6-build126149 | |
Zohocorp ManageEngine OpManager | =12.6-build126150 | |
Zohocorp ManageEngine OpManager | =12.6-build126151 | |
Zohocorp ManageEngine OpManager | =12.6-build126154 | |
Zohocorp ManageEngine OpManager | =12.6-build126155 | |
Zohocorp ManageEngine OpManager | =12.6-build126162 | |
Zohocorp ManageEngine OpManager | =12.6-build126163 | |
Zohocorp ManageEngine OpManager | =12.6-build126164 | |
Zohocorp ManageEngine OpManager | =12.6-build126165 | |
Zohocorp ManageEngine OpManager | =12.6-build126166 | |
Zohocorp ManageEngine OpManager | =12.6-build126167 | |
Zohocorp ManageEngine OpManager | =12.6-build126168 | |
Zohocorp Manageengine Opmanager Plus | <12.6 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126001 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126002 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126100 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126103 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126104 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126107 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126113 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126117 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126119 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126122 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126139 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126140 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126141 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126154 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126155 | |
Zohocorp Manageengine Opmanager Plus | =12.6-build126264 | |
Zohocorp Manageengine Opmanager Msp | <12.6 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126001 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126002 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126100 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126103 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126104 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126107 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126113 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126117 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126119 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126122 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126139 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126140 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126141 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126154 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126155 | |
Zohocorp Manageengine Opmanager Msp | =12.6-build126264 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.