CVE-2015-9107
04.08.2017, 00:29
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.Enginsight
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_opmanager | 11.0 |
| zohocorp | manageengine_opmanager | 11.1 |
| zohocorp | manageengine_opmanager | 11.2 |
| zohocorp | manageengine_opmanager | 11.3 |
| zohocorp | manageengine_opmanager | 11.4 |
| zohocorp | manageengine_opmanager | 11.5 |
| zohocorp | manageengine_opmanager | 11.6 |
| zohocorp | manageengine_opmanager | 12.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration