PT-2022-23689 · Zoho · Opmanager+6
Published
2022-08-10
·
Updated
2025-09-24
·
CVE-2022-36923
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine OpManager versions before 2022-07-27 through 2022-07-28
Zoho ManageEngine OpManager Plus versions before 2022-07-27 through 2022-07-28
Zoho ManageEngine OpManager MSP versions before 2022-07-27 through 2022-07-28
Zoho ManageEngine Network Configuration Manager versions before 2022-07-27 through 2022-07-28
Zoho ManageEngine NetFlow Analyzer versions before 2022-07-27 through 2022-07-28
Zoho ManageEngine Firewall Analyzer versions before 2022-07-27 through 2022-07-28
Zoho ManageEngine OpUtils versions before 2022-07-27 through 2022-07-28
Description
The issue allows unauthenticated attackers to obtain a user's API key, and then access external APIs. This is achieved through an authentication bypass vulnerability in the
getUserAPIKey function.Recommendations
For Zoho ManageEngine OpManager versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28.
For Zoho ManageEngine OpManager Plus versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28.
For Zoho ManageEngine OpManager MSP versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28.
For Zoho ManageEngine Network Configuration Manager versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28.
For Zoho ManageEngine NetFlow Analyzer versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28.
For Zoho ManageEngine Firewall Analyzer versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28.
For Zoho ManageEngine OpUtils versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28.
As a temporary workaround, consider disabling the
getUserAPIKey function until a patch is available.Fix
Improper Access Control
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firewall Analyzer
Netflow Analyzer
Network Configuration Manager
Opmanager
Opmanager Msp
Opmanager Plus
Oputils