CVE-2021-41075

CVSS V2 High 7.5 CVSS V3 Critical 9.8
Description
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
Overview
  • CVE ID
  • CVE-2021-41075
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2021-10-13T23:15:07
  • Last Modified Date
  • 2021-10-19T20:11:39
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:* 1 OR 12.5
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:-:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125000:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125002:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125100:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125101:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125102:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125108:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125110:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125111:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125112:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125113:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125114:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125116:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125117:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125118:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125120:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125121:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125123:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125124:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125125:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125136:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125137:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125139:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125140:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125143:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125144:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125145:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125156:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125157:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125158:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125159:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125161:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125163:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125174:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125175:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125176:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125177:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125178:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125180:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125181:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125192:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125193:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125194:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125195:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125196:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125197:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125198:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125201:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125204:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125212:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125213:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125214:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125215:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125216:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125228:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125229:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125230:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125231:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125232:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125233:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125312:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125323:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125324:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125326:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125328:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125329:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125340:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125341:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125342:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125343:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125344:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125346:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125358:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125359:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125360:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125361:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125362:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125364:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125366:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125367:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125375:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125376:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125377:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125378:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125379:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125380:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125381:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125382:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125386:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125392:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125393:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125394:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125397:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125398:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125399:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125405:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125410:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125411:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125413:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125414:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125415:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125416:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125417:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125420:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125428:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125430:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125431:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125432:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125433:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125434:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125437:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125446:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125448:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125450:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125451:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125452:*:*:*:*:*:* 1 OR
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5:build125453:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:L/Au:N/C:P/I:P/A:P
  • Access Vector
  • NETWORK
  • Access Compatibility
  • LOW
  • Authentication
  • NONE
  • Confidentiality Impact
  • PARTIAL
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • PARTIAL
  • Base Score
  • 7.5
  • Severity
  • HIGH
  • Exploitability Score
  • 10
  • Impact Score
  • 6.4
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • NONE
  • Scope
  • UNCHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • HIGH
  • Base Score
  • 9.8
  • Base Severity
  • CRITICAL
  • Exploitability Score
  • 3.9
  • Impact Score
  • 5.9
References
Reference URL Reference Tags
https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_125455 Release Notes Vendor Advisory
History
Created Old Value New Value Data Type Notes
2022-05-10 06:50:24 Added to TrackCVE
2022-12-05 12:25:07 2021-10-13T23:15Z 2021-10-13T23:15:07 CVE Published Date updated
2022-12-05 12:25:07 2021-10-19T20:11:39 CVE Modified Date updated
2022-12-05 12:25:08 Analyzed Vulnerability Status updated