Improper Authentication in ManageEngine Applications Manager and Zoho ManageEngine OpManager - CVE-2019-15106

 

Improper Authentication in ManageEngine Applications Manager and Zoho ManageEngine OpManager - CVE-2019-15106

Published: October 16, 2019


Vulnerability identifier: #VU21880
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-15106
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to improper implementation of authentication process that relies on username+'@opm' string to be used as password within the Application Manager Plugin used in ManageEngine OpManager and Applications Manager. A remote attacker can bypass authentication process and execute arbitrary commands on the system with privileges of the user account.


Affected software

ManageEngine Applications Manager
Zoho ManageEngine OpManager

How to mitigate CVE-2019-15106

Install updates from vendor's website.

ManageEngine Applications Manager - update to 14.3 14310
Zoho ManageEngine OpManager - addressed in versions 12.4 124062, 12.4 124070

External References

Related Security Bulletins