CVE-2020-12116: Zohocorp ManageEngine Opmanager

High severity, CVSS 7.5. EPSS: 97.4% chance of exploitation in the next 30 days.

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

Affected products

  • Zohocorp ManageEngine Opmanager: up to and including 12.3; version 12.4 only; version 12.5 only

Published 2020-05-07. Last modified 2026-06-17.