Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hc4f-4mvr-7cv9

Опубликовано: 11 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

EPSS

Процентиль: 98%
0.46848
Средний

7.5 High

CVSS3

Дефекты

CWE-284
CWE-755

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.

EPSS

Процентиль: 98%
0.46848
Средний

7.5 High

CVSS3

Дефекты

CWE-284
CWE-755