CRITICAL
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet
Published Feb 3, 2021
9.8
CRITICALCVSS 3.1
EPSS 78.70%
Description
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
Affected products
No data.
OR
- < 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
- 12.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (3)
- http://packetstormsecurity.com/files/164231/ManageEngine-OpManager-SumPDU-Java-Deserialization.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125203 x_refsource_CONFIRMRelease NotesVendor Advisory
- https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125233 x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/164231/ManageEngine-OpManager-SumPDU-Java-Deserialization.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125203 | x_refsource_CONFIRMRelease NotesVendor Advisory | |
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125233 | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 3, 2021
Updated Aug 4, 2024
Reserved Nov 16, 2020
Link CVE-2020-28653
CISA Vulnrichment
Updated n/a