CVE-2015-9107: Zohocorp ManageEngine Opmanager
Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.
Affected products
- Zohocorp ManageEngine Opmanager: version 11.0 only; version 11.1 only; version 11.2 only; version 11.3 only; version 11.4 only; version 11.5 only; …
Published 2017-08-04. Last modified 2026-06-17.