Improper access control in Zoho ManageEngine OpManager - #VU60180

 

Improper access control in Zoho ManageEngine OpManager - #VU60180

Published: January 31, 2022


Vulnerability identifier: #VU60180
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in NCM. A remote user can bypass implemented security restrictions and view alarms of other devices in alarm popups and dashboard widget.


Affected software

Zoho ManageEngine OpManager

Remediation

Install updates from vendor's website.

Zoho ManageEngine OpManager - update to 12.5 125565

External References

Related Security Bulletins