Lucene search

K
nvd[email protected]NVD:CVE-2021-41075
HistoryOct 13, 2021 - 11:15 p.m.

CVE-2021-41075

2021-10-1323:15:07
CWE-89
web.nvd.nist.gov
6
netflow analyzer
zoho manageengine
opmanager
sql injection
vulnerability
attacks module api

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.023

Percentile

89.9%

The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.

Affected configurations

Nvd
Node
zohocorpmanageengine_opmanagerRange<12.5
OR
zohocorpmanageengine_opmanagerMatch12.5-
OR
zohocorpmanageengine_opmanagerMatch12.5build125000
OR
zohocorpmanageengine_opmanagerMatch12.5build125002
OR
zohocorpmanageengine_opmanagerMatch12.5build125100
OR
zohocorpmanageengine_opmanagerMatch12.5build125101
OR
zohocorpmanageengine_opmanagerMatch12.5build125102
OR
zohocorpmanageengine_opmanagerMatch12.5build125108
OR
zohocorpmanageengine_opmanagerMatch12.5build125110
OR
zohocorpmanageengine_opmanagerMatch12.5build125111
OR
zohocorpmanageengine_opmanagerMatch12.5build125112
OR
zohocorpmanageengine_opmanagerMatch12.5build125113
OR
zohocorpmanageengine_opmanagerMatch12.5build125114
OR
zohocorpmanageengine_opmanagerMatch12.5build125116
OR
zohocorpmanageengine_opmanagerMatch12.5build125117
OR
zohocorpmanageengine_opmanagerMatch12.5build125118
OR
zohocorpmanageengine_opmanagerMatch12.5build125120
OR
zohocorpmanageengine_opmanagerMatch12.5build125121
OR
zohocorpmanageengine_opmanagerMatch12.5build125123
OR
zohocorpmanageengine_opmanagerMatch12.5build125124
OR
zohocorpmanageengine_opmanagerMatch12.5build125125
OR
zohocorpmanageengine_opmanagerMatch12.5build125136
OR
zohocorpmanageengine_opmanagerMatch12.5build125137
OR
zohocorpmanageengine_opmanagerMatch12.5build125139
OR
zohocorpmanageengine_opmanagerMatch12.5build125140
OR
zohocorpmanageengine_opmanagerMatch12.5build125143
OR
zohocorpmanageengine_opmanagerMatch12.5build125144
OR
zohocorpmanageengine_opmanagerMatch12.5build125145
OR
zohocorpmanageengine_opmanagerMatch12.5build125156
OR
zohocorpmanageengine_opmanagerMatch12.5build125157
OR
zohocorpmanageengine_opmanagerMatch12.5build125158
OR
zohocorpmanageengine_opmanagerMatch12.5build125159
OR
zohocorpmanageengine_opmanagerMatch12.5build125161
OR
zohocorpmanageengine_opmanagerMatch12.5build125163
OR
zohocorpmanageengine_opmanagerMatch12.5build125174
OR
zohocorpmanageengine_opmanagerMatch12.5build125175
OR
zohocorpmanageengine_opmanagerMatch12.5build125176
OR
zohocorpmanageengine_opmanagerMatch12.5build125177
OR
zohocorpmanageengine_opmanagerMatch12.5build125178
OR
zohocorpmanageengine_opmanagerMatch12.5build125180
OR
zohocorpmanageengine_opmanagerMatch12.5build125181
OR
zohocorpmanageengine_opmanagerMatch12.5build125192
OR
zohocorpmanageengine_opmanagerMatch12.5build125193
OR
zohocorpmanageengine_opmanagerMatch12.5build125194
OR
zohocorpmanageengine_opmanagerMatch12.5build125195
OR
zohocorpmanageengine_opmanagerMatch12.5build125196
OR
zohocorpmanageengine_opmanagerMatch12.5build125197
OR
zohocorpmanageengine_opmanagerMatch12.5build125198
OR
zohocorpmanageengine_opmanagerMatch12.5build125201
OR
zohocorpmanageengine_opmanagerMatch12.5build125204
OR
zohocorpmanageengine_opmanagerMatch12.5build125212
OR
zohocorpmanageengine_opmanagerMatch12.5build125213
OR
zohocorpmanageengine_opmanagerMatch12.5build125214
OR
zohocorpmanageengine_opmanagerMatch12.5build125215
OR
zohocorpmanageengine_opmanagerMatch12.5build125216
OR
zohocorpmanageengine_opmanagerMatch12.5build125228
OR
zohocorpmanageengine_opmanagerMatch12.5build125229
OR
zohocorpmanageengine_opmanagerMatch12.5build125230
OR
zohocorpmanageengine_opmanagerMatch12.5build125231
OR
zohocorpmanageengine_opmanagerMatch12.5build125232
OR
zohocorpmanageengine_opmanagerMatch12.5build125233
OR
zohocorpmanageengine_opmanagerMatch12.5build125312
OR
zohocorpmanageengine_opmanagerMatch12.5build125323
OR
zohocorpmanageengine_opmanagerMatch12.5build125324
OR
zohocorpmanageengine_opmanagerMatch12.5build125326
OR
zohocorpmanageengine_opmanagerMatch12.5build125328
OR
zohocorpmanageengine_opmanagerMatch12.5build125329
OR
zohocorpmanageengine_opmanagerMatch12.5build125340
OR
zohocorpmanageengine_opmanagerMatch12.5build125341
OR
zohocorpmanageengine_opmanagerMatch12.5build125342
OR
zohocorpmanageengine_opmanagerMatch12.5build125343
OR
zohocorpmanageengine_opmanagerMatch12.5build125344
OR
zohocorpmanageengine_opmanagerMatch12.5build125346
OR
zohocorpmanageengine_opmanagerMatch12.5build125358
OR
zohocorpmanageengine_opmanagerMatch12.5build125359
OR
zohocorpmanageengine_opmanagerMatch12.5build125360
OR
zohocorpmanageengine_opmanagerMatch12.5build125361
OR
zohocorpmanageengine_opmanagerMatch12.5build125362
OR
zohocorpmanageengine_opmanagerMatch12.5build125364
OR
zohocorpmanageengine_opmanagerMatch12.5build125366
OR
zohocorpmanageengine_opmanagerMatch12.5build125367
OR
zohocorpmanageengine_opmanagerMatch12.5build125375
OR
zohocorpmanageengine_opmanagerMatch12.5build125376
OR
zohocorpmanageengine_opmanagerMatch12.5build125377
OR
zohocorpmanageengine_opmanagerMatch12.5build125378
OR
zohocorpmanageengine_opmanagerMatch12.5build125379
OR
zohocorpmanageengine_opmanagerMatch12.5build125380
OR
zohocorpmanageengine_opmanagerMatch12.5build125381
OR
zohocorpmanageengine_opmanagerMatch12.5build125382
OR
zohocorpmanageengine_opmanagerMatch12.5build125386
OR
zohocorpmanageengine_opmanagerMatch12.5build125392
OR
zohocorpmanageengine_opmanagerMatch12.5build125393
OR
zohocorpmanageengine_opmanagerMatch12.5build125394
OR
zohocorpmanageengine_opmanagerMatch12.5build125397
OR
zohocorpmanageengine_opmanagerMatch12.5build125398
OR
zohocorpmanageengine_opmanagerMatch12.5build125399
OR
zohocorpmanageengine_opmanagerMatch12.5build125405
OR
zohocorpmanageengine_opmanagerMatch12.5build125410
OR
zohocorpmanageengine_opmanagerMatch12.5build125411
OR
zohocorpmanageengine_opmanagerMatch12.5build125413
OR
zohocorpmanageengine_opmanagerMatch12.5build125414
OR
zohocorpmanageengine_opmanagerMatch12.5build125415
OR
zohocorpmanageengine_opmanagerMatch12.5build125416
OR
zohocorpmanageengine_opmanagerMatch12.5build125417
OR
zohocorpmanageengine_opmanagerMatch12.5build125420
OR
zohocorpmanageengine_opmanagerMatch12.5build125428
OR
zohocorpmanageengine_opmanagerMatch12.5build125430
OR
zohocorpmanageengine_opmanagerMatch12.5build125431
OR
zohocorpmanageengine_opmanagerMatch12.5build125432
OR
zohocorpmanageengine_opmanagerMatch12.5build125433
OR
zohocorpmanageengine_opmanagerMatch12.5build125434
OR
zohocorpmanageengine_opmanagerMatch12.5build125437
OR
zohocorpmanageengine_opmanagerMatch12.5build125446
OR
zohocorpmanageengine_opmanagerMatch12.5build125448
OR
zohocorpmanageengine_opmanagerMatch12.5build125450
OR
zohocorpmanageengine_opmanagerMatch12.5build125451
OR
zohocorpmanageengine_opmanagerMatch12.5build125452
OR
zohocorpmanageengine_opmanagerMatch12.5build125453
VendorProductVersionCPE
zohocorpmanageengine_opmanager*cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:-:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125000:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125002:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125100:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125101:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125102:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125108:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125110:*:*:*:*:*:*
zohocorpmanageengine_opmanager12.5cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125111:*:*:*:*:*:*
Rows per page:
1-10 of 1181

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.023

Percentile

89.9%

Related for NVD:CVE-2021-41075