SB2022072924 - Remote code execution in Zoho ManageEngine OpManager
Published: July 29, 2022 Updated: September 5, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Use of Obsolete Function (CVE-ID: CVE-2022-37024)
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to presence of an unused API endpoint, which is prone to OS command injection within the getDNSResolveOption function. A remote attacker can send a specially crafted request to the application and execute arbitrary code on the system.
2) OS Command Injection (CVE-ID: CVE-2022-38772)
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the getNmapInitialOption function in API. A remote user can send specially crafted data to the application and execute arbitrary OS commands with elevated privileges.
Remediation
Install update from vendor's website.
References
- https://www.manageengine.com/network-monitoring/help/read-me-complete.html#126120
- https://www.zerodayinitiative.com/advisories/ZDI-22-1179/
- https://www.zerodayinitiative.com/advisories/ZDI-22-1184/
- https://manageengine.com
- https://www.manageengine.com/itom/advisory/cve-2022-38772.html
- https://www.zerodayinitiative.com/advisories/ZDI-22-1182/
- https://www.zerodayinitiative.com/advisories/ZDI-22-1181/