Skip to content

Conversation

@daffainfo
Copy link
Contributor

PR Information

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

Template validation

  • Validated with a host running a vulnerable version and/or configuration (True Positive)
  • Validated with a host running a patched version and/or configuration (avoid False Positive)

Notes

Researched this with @jjchoNC

@pussycat0x pussycat0x added Status: In Progress This issue is being worked on, and has someone assigned. and removed Done Ready to merge labels Dec 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Status: In Progress This issue is being worked on, and has someone assigned.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants