Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43473


A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.


Published

2023-03-30T17:15:06.750

Last Modified

2024-11-21T07:26:33.497

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zohocorp manageengine_opmanager < 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager 12.6 Yes
Application zohocorp manageengine_opmanager_plus < 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_plus 12.6 Yes
Application zohocorp manageengine_opmanager_msp < 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes
Application zohocorp manageengine_opmanager_msp 12.6 Yes

References