Vulnerability Description
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Firewall Analyzer | 12.5 |
| Zohocorp | Manageengine Netflow Analyzer | 12.5 |
| Zohocorp | Manageengine Network Configuration Manager | 12.5 |
| Zohocorp | Manageengine Opmanager | 12.5 |
| Zohocorp | Manageengine Opmanager Msp | 12.5 |
| Zohocorp | Manageengine Opmanager Plus | 12.5 |
| Zohocorp | Manageengine Oputils | 12.5 |
Related Weaknesses (CWE)
References
- https://www.manageengine.com/itom/advisory/cve-2022-36923.htmlVendor Advisory
- https://www.manageengine.com/itom/advisory/cve-2022-36923.htmlVendor Advisory
FAQ
What is CVE-2022-36923?
CVE-2022-36923 is a vulnerability with a CVSS score of 7.5 (HIGH). Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104...
How severe is CVE-2022-36923?
CVE-2022-36923 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36923?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Firewall Analyzer, Zohocorp Manageengine Netflow Analyzer, Zohocorp Manageengine Network Configuration Manager, Zohocorp Manageengine Opmanager, Zohocorp Manageengine Opmanager Msp.