CVE-2019-15106

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
16/08/2019
Last modified:
24/08/2020

Description

An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zohocorp:manageengine_opmanager:*:*:*:*:*:*:*:* 12.4.034 (including)