CVE-2022-38772
Last modified
CVE-2022-38772 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.. EPSS estimates a 77.62% chance of exploitation in the next 30 days.
Description
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Zohocorp | Manageengine Netflow Analyzer | 12.5 | Build125450 |
| Zohocorp | Manageengine Netflow Analyzer | 12.6 | Build126000 |
| Zohocorp | Manageengine Network Configuration Manager | 12.5 | Build125450 |
| Zohocorp | Manageengine Network Configuration Manager | 12.6 | Build126000 |
| Zohocorp | Manageengine Opmanager | 12.5 | Build125450 |
| Zohocorp | Manageengine Opmanager | 12.6 | Build126000 |
| Zohocorp | Manageengine Opmanager Msp | 12.5 | Build125450 |
| Zohocorp | Manageengine Opmanager Msp | 12.6 | Build126000 |
| Zohocorp | Manageengine Opmanager Plus | 12.5 | Build125450 |
| Zohocorp | Manageengine Opmanager Plus | 12.6 | Build126000 |
| Zohocorp | Manageengine Oputils | 12.5 | Build125450 |
| Zohocorp | Manageengine Oputils | 12.6 | Build126000 |
References
- https://manageengine.comVendor Advisory
- https://manageengine.comVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-38772?
How severe is CVE-2022-38772?
How do I fix CVE-2022-38772?
Are you affected by CVE-2022-38772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
