CVE-2019-15106
16.08.2019, 03:15
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_opmanager | 𝑥 ≤ 12.4.034 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References