Total vulnerabilities in the database
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.
Software | From | Fixed in |
---|---|---|
zohocorp / manageengine_opmanager | 11.5 | 11.5.x |
zohocorp / manageengine_opmanager | 11.3 | 11.3.x |
zohocorp / manageengine_opmanager | 11.4 | 11.4.x |
zohocorp / manageengine_opmanager | 11.0 | 11.0.x |
zohocorp / manageengine_opmanager | 11.1 | 11.1.x |
zohocorp / manageengine_opmanager | 11.6 | 11.6.x |
zohocorp / manageengine_opmanager | 12.2 | 12.2.x |
zohocorp / manageengine_opmanager | 11.2 | 11.2.x |