Vulnerability Description
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Firewall Analyzer | 12.5 |
| Zohocorp | Manageengine Netflow Analyzer | 12.5 |
| Zohocorp | Manageengine Network Configuration Manager | 12.5 |
| Zohocorp | Manageengine Opmanager | 12.5 |
| Zohocorp | Manageengine Opmanager Msp | 12.5 |
| Zohocorp | Manageengine Opmanager Plus | 12.5 |
| Zohocorp | Manageengine Oputils | 12.5 |
References
- https://www.manageengine.com/itom/advisory/cve-2022-37024.htmlVendor Advisory
- https://www.manageengine.com/itom/advisory/cve-2022-37024.htmlVendor Advisory
FAQ
What is CVE-2022-37024?
CVE-2022-37024 is a vulnerability with a CVSS score of 8.8 (HIGH). Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allo...
How severe is CVE-2022-37024?
CVE-2022-37024 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-37024?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Firewall Analyzer, Zohocorp Manageengine Netflow Analyzer, Zohocorp Manageengine Network Configuration Manager, Zohocorp Manageengine Opmanager, Zohocorp Manageengine Opmanager Msp.