ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.
References
Configurations
History
No history.
Information
Published : 2015-10-09 14:59
Updated : 2015-10-09 17:42
NVD link : CVE-2015-7765
Mitre link : CVE-2015-7765
CVE.ORG link : CVE-2015-7765
JSON object : View
Products Affected
zohocorp
- manageengine_opmanager
CWE