An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
                
            References
                    | Link | Resource | 
|---|---|
| http://manageengine.com | Vendor Advisory | 
| http://opmanager.com | Product | 
| https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18736 | Exploit Third Party Advisory | 
| http://manageengine.com | Vendor Advisory | 
| http://opmanager.com | Product | 
| https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18736 | Exploit Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 03:08
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://manageengine.com - Vendor Advisory | |
| References | () http://opmanager.com - Product | |
| References | () https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18736 - Exploit, Third Party Advisory | 
Information
                Published : 2019-05-23 18:29
Updated : 2024-11-21 03:08
NVD link : CVE-2017-11559
Mitre link : CVE-2017-11559
CVE.ORG link : CVE-2017-11559
JSON object : View
Products Affected
                zohocorp
- manageengine_opmanager
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
