CVE-2019-15104
ManageEngine OpManager 12.4x - Privilege Escalation / Remote Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.
Se detectó un problema en Zoho ManageEngine OpManager versiones hasta 12.4x. Se presenta una vulnerabilidad de inyección SQL en el archivo jsp/NewThresholdConfiguration.jsp por medio del parámetro resourceid. Por lo tanto, un usuario con poca autoridad puede conseguir la autoridad de SYSTEM en el servidor. En consecuencia, se puede cargar un archivo malicioso utilizando la funcionalidad "Execute Program Action(s)".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-08-15 CVE Reserved
- 2019-08-16 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-08-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/47227 | 2024-08-05 | |
http://pentest.com.tr/exploits/DEFCON-ManageEngine-OpManager-v12-4-Privilege-Escalation-Remote-Command-Execution.html | 2024-08-05 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Applications Manager Search vendor "Zohocorp" for product "Manageengine Applications Manager" | >= 12.0 <= 14.0 Search vendor "Zohocorp" for product "Manageengine Applications Manager" and version " >= 12.0 <= 14.0" | - |
Affected
|