CVE-2019-17602

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:-:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124000:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124011:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124012:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124013:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124014:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124015:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124016:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124022:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124023:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124024:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124025:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124026:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124027:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124030:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124033:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124037:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124039:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124040:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124041:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124042:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124043:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124051:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124053:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124054:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124056:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124058:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124065:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124066:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124067:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124069:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124070:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124071:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124074:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124075:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124081:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124082:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124085:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124086:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124087:*:*:*:*:*:*

History

04 May 2021, 14:34

Type Values Removed Values Added
CPE cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124013:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124014:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124000:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124011:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124012:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124014:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124013:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124000:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124012:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124011:*:*:*:*:*:*

29 Apr 2021, 18:18

Type Values Removed Values Added
CPE cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124066:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124054:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124016:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124085:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124022:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124067:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124024:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124086:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124074:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124015:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124082:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124033:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124025:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124081:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124026:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124058:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124042:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124023:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124027:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124039:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124051:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124056:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124040:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124075:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124053:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124065:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124070:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124037:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124071:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124069:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124030:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124043:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124041:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:124087:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124082:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124067:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124043:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124042:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124030:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124081:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124015:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124033:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124054:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124074:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124025:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124086:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124040:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124051:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124071:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124026:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124039:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124065:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124024:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124016:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124027:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124066:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124075:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124070:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124058:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124069:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124022:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124023:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124056:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124053:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124041:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124087:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124037:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4:build124085:*:*:*:*:*:*

Information

Published : 2019-10-15 21:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-17602

Mitre link : CVE-2019-17602

CVE.ORG link : CVE-2019-17602


JSON object : View

Products Affected

zohocorp

  • manageengine_opmanager
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')