CVE-2018-17283: Zohocorp ManageEngine Opmanager

High severity, CVSS 7.5. EPSS: 66.3% chance of exploitation in the next 30 days.

Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or conduct a SQL Injection attack via the /api/json/device/setManaged name parameter.

Affected products

  • Zohocorp ManageEngine Opmanager: before 12.3 (fixed in 12.3)

Published 2018-09-21. Last modified 2026-06-17.