CWE
611 918
Advisory Published
Updated

CVE-2022-43473: XEE

First published: Thu Mar 30 2023(Updated: )

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

Credit: talos-cna@cisco.com

Affected SoftwareAffected VersionHow to fix
Zohocorp Manageengine Opmanager<12.6
Zohocorp Manageengine Opmanager=12.6-build126000
Zohocorp Manageengine Opmanager=12.6-build126001
Zohocorp Manageengine Opmanager=12.6-build126002
Zohocorp Manageengine Opmanager=12.6-build126004
Zohocorp Manageengine Opmanager=12.6-build126005
Zohocorp Manageengine Opmanager=12.6-build126100
Zohocorp Manageengine Opmanager=12.6-build126101
Zohocorp Manageengine Opmanager=12.6-build126102
Zohocorp Manageengine Opmanager=12.6-build126103
Zohocorp Manageengine Opmanager=12.6-build126104
Zohocorp Manageengine Opmanager=12.6-build126107
Zohocorp Manageengine Opmanager=12.6-build126108
Zohocorp Manageengine Opmanager=12.6-build126109
Zohocorp Manageengine Opmanager=12.6-build126110
Zohocorp Manageengine Opmanager=12.6-build126113
Zohocorp Manageengine Opmanager=12.6-build126114
Zohocorp Manageengine Opmanager=12.6-build126115
Zohocorp Manageengine Opmanager=12.6-build126116
Zohocorp Manageengine Opmanager=12.6-build126117
Zohocorp Manageengine Opmanager=12.6-build126118
Zohocorp Manageengine Opmanager=12.6-build126119
Zohocorp Manageengine Opmanager=12.6-build126120
Zohocorp Manageengine Opmanager=12.6-build126121
Zohocorp Manageengine Opmanager=12.6-build126122
Zohocorp Manageengine Opmanager=12.6-build126130
Zohocorp Manageengine Opmanager=12.6-build126131
Zohocorp Manageengine Opmanager=12.6-build126132
Zohocorp Manageengine Opmanager=12.6-build126134
Zohocorp Manageengine Opmanager=12.6-build126135
Zohocorp Manageengine Opmanager=12.6-build126136
Zohocorp Manageengine Opmanager=12.6-build126139
Zohocorp Manageengine Opmanager=12.6-build126141
Zohocorp Manageengine Opmanager=12.6-build126147
Zohocorp Manageengine Opmanager=12.6-build126148
Zohocorp Manageengine Opmanager=12.6-build126149
Zohocorp Manageengine Opmanager=12.6-build126150
Zohocorp Manageengine Opmanager=12.6-build126151
Zohocorp Manageengine Opmanager=12.6-build126154
Zohocorp Manageengine Opmanager=12.6-build126155
Zohocorp Manageengine Opmanager=12.6-build126162
Zohocorp Manageengine Opmanager=12.6-build126163
Zohocorp Manageengine Opmanager=12.6-build126164
Zohocorp Manageengine Opmanager=12.6-build126165
Zohocorp Manageengine Opmanager=12.6-build126166
Zohocorp Manageengine Opmanager=12.6-build126167
Zohocorp Manageengine Opmanager=12.6-build126168
Zohocorp Manageengine Opmanager Plus<12.6
Zohocorp Manageengine Opmanager Plus=12.6-build126001
Zohocorp Manageengine Opmanager Plus=12.6-build126002
Zohocorp Manageengine Opmanager Plus=12.6-build126100
Zohocorp Manageengine Opmanager Plus=12.6-build126103
Zohocorp Manageengine Opmanager Plus=12.6-build126104
Zohocorp Manageengine Opmanager Plus=12.6-build126107
Zohocorp Manageengine Opmanager Plus=12.6-build126113
Zohocorp Manageengine Opmanager Plus=12.6-build126117
Zohocorp Manageengine Opmanager Plus=12.6-build126119
Zohocorp Manageengine Opmanager Plus=12.6-build126122
Zohocorp Manageengine Opmanager Plus=12.6-build126139
Zohocorp Manageengine Opmanager Plus=12.6-build126140
Zohocorp Manageengine Opmanager Plus=12.6-build126141
Zohocorp Manageengine Opmanager Plus=12.6-build126154
Zohocorp Manageengine Opmanager Plus=12.6-build126155
Zohocorp Manageengine Opmanager Plus=12.6-build126264
Zohocorp Manageengine Opmanager Msp<12.6
Zohocorp Manageengine Opmanager Msp=12.6-build126001
Zohocorp Manageengine Opmanager Msp=12.6-build126002
Zohocorp Manageengine Opmanager Msp=12.6-build126100
Zohocorp Manageengine Opmanager Msp=12.6-build126103
Zohocorp Manageengine Opmanager Msp=12.6-build126104
Zohocorp Manageengine Opmanager Msp=12.6-build126107
Zohocorp Manageengine Opmanager Msp=12.6-build126113
Zohocorp Manageengine Opmanager Msp=12.6-build126117
Zohocorp Manageengine Opmanager Msp=12.6-build126119
Zohocorp Manageengine Opmanager Msp=12.6-build126122
Zohocorp Manageengine Opmanager Msp=12.6-build126139
Zohocorp Manageengine Opmanager Msp=12.6-build126140
Zohocorp Manageengine Opmanager Msp=12.6-build126141
Zohocorp Manageengine Opmanager Msp=12.6-build126154
Zohocorp Manageengine Opmanager Msp=12.6-build126155
Zohocorp Manageengine Opmanager Msp=12.6-build126264

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203