PT-2022-23689 · Zoho · Opmanager+6

Published

2022-08-10

·

Updated

2025-09-24

·

CVE-2022-36923

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine OpManager versions before 2022-07-27 through 2022-07-28 Zoho ManageEngine OpManager Plus versions before 2022-07-27 through 2022-07-28 Zoho ManageEngine OpManager MSP versions before 2022-07-27 through 2022-07-28 Zoho ManageEngine Network Configuration Manager versions before 2022-07-27 through 2022-07-28 Zoho ManageEngine NetFlow Analyzer versions before 2022-07-27 through 2022-07-28 Zoho ManageEngine Firewall Analyzer versions before 2022-07-27 through 2022-07-28 Zoho ManageEngine OpUtils versions before 2022-07-27 through 2022-07-28
Description The issue allows unauthenticated attackers to obtain a user's API key, and then access external APIs. This is achieved through an authentication bypass vulnerability in the getUserAPIKey function.
Recommendations For Zoho ManageEngine OpManager versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28. For Zoho ManageEngine OpManager Plus versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28. For Zoho ManageEngine OpManager MSP versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28. For Zoho ManageEngine Network Configuration Manager versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28. For Zoho ManageEngine NetFlow Analyzer versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28. For Zoho ManageEngine Firewall Analyzer versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28. For Zoho ManageEngine OpUtils versions before 2022-07-27 through 2022-07-28, update to a version released after 2022-07-28. As a temporary workaround, consider disabling the getUserAPIKey function until a patch is available.

Fix

Improper Access Control

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2022-36923
ZDI-22-1119
ZDI-22-1120
ZDI-22-1121
ZDI-22-1122

Affected Products

Firewall Analyzer
Netflow Analyzer
Network Configuration Manager
Opmanager
Opmanager Msp
Opmanager Plus
Oputils