CVE-2018-17283 describes an authentication bypass vulnerability in Zoho ManageEngine OpManager versions prior to 12.3 Build 123196, specifically affecting /oputilsServlet requests. This flaw allows unauthenticated attackers to retrieve API keys, which can then be used to add administrative users to Firewall Analyzer or conduct SQL injection attacks through the /api/json/device/setManaged name parameter. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to full compromise of confidentiality. While there is no evidence of active exploitation (KEV: No), exploit templates exist for SQL injection, and its EPSS score indicates a higher than average likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.3CPE matchmatch criteria | cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.