Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/theguly/DecryptOpManager | Third Party Advisory | 
| https://github.com/theguly/DecryptOpManager | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 02:39
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/theguly/DecryptOpManager - Third Party Advisory | 
Information
                Published : 2017-08-04 00:29
Updated : 2025-04-20 01:37
NVD link : CVE-2015-9107
Mitre link : CVE-2015-9107
CVE.ORG link : CVE-2015-9107
JSON object : View
Products Affected
                zohocorp
- manageengine_opmanager
CWE
                
                    
                        
                        CWE-310
                        
            Cryptographic Issues
