CVE Vulnerabilities

CVE-2022-36923

Improper Handling of Exceptional Conditions

Published: Aug 10, 2022 | Modified: Sep 24, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a users API key, and then access external APIs.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_firewall_analyzerZohocorp12.5-build125450 (including)12.5-build125450 (including)
Manageengine_firewall_analyzerZohocorp12.5-build125451 (including)12.5-build125451 (including)
Manageengine_firewall_analyzerZohocorp12.5-build125452 (including)12.5-build125452 (including)
Manageengine_firewall_analyzerZohocorp12.5-build125453 (including)12.5-build125453 (including)
Manageengine_firewall_analyzerZohocorp12.5-build125455 (including)12.5-build125455 (including)
Manageengine_firewall_analyzerZohocorp12.5-build125456 (including)12.5-build125456 (including)
Manageengine_firewall_analyzerZohocorp12.5-build125664 (including)12.5-build125664 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126000 (including)12.6-build126000 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126001 (including)12.6-build126001 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126100 (including)12.6-build126100 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126101 (including)12.6-build126101 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126102 (including)12.6-build126102 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126103 (including)12.6-build126103 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126113 (including)12.6-build126113 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126114 (including)12.6-build126114 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126115 (including)12.6-build126115 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126116 (including)12.6-build126116 (including)
Manageengine_firewall_analyzerZohocorp12.6-build126117 (including)12.6-build126117 (including)
Manageengine_netflow_analyzerZohocorp12.5-build125450 (including)12.5-build125450 (including)
Manageengine_netflow_analyzerZohocorp12.5-build125451 (including)12.5-build125451 (including)
Manageengine_netflow_analyzerZohocorp12.5-build125452 (including)12.5-build125452 (including)
Manageengine_netflow_analyzerZohocorp12.5-build125453 (including)12.5-build125453 (including)
Manageengine_netflow_analyzerZohocorp12.5-build125455 (including)12.5-build125455 (including)
Manageengine_netflow_analyzerZohocorp12.5-build125456 (including)12.5-build125456 (including)
Manageengine_netflow_analyzerZohocorp12.5-build125664 (including)12.5-build125664 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126000 (including)12.6-build126000 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126001 (including)12.6-build126001 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126100 (including)12.6-build126100 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126101 (including)12.6-build126101 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126102 (including)12.6-build126102 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126103 (including)12.6-build126103 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126113 (including)12.6-build126113 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126114 (including)12.6-build126114 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126115 (including)12.6-build126115 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126116 (including)12.6-build126116 (including)
Manageengine_netflow_analyzerZohocorp12.6-build126117 (including)12.6-build126117 (including)
Manageengine_network_configuration_managerZohocorp12.5-build125450 (including)12.5-build125450 (including)
Manageengine_network_configuration_managerZohocorp12.5-build125451 (including)12.5-build125451 (including)
Manageengine_network_configuration_managerZohocorp12.5-build125452 (including)12.5-build125452 (including)
Manageengine_network_configuration_managerZohocorp12.5-build125453 (including)12.5-build125453 (including)
Manageengine_network_configuration_managerZohocorp12.5-build125455 (including)12.5-build125455 (including)
Manageengine_network_configuration_managerZohocorp12.5-build125456 (including)12.5-build125456 (including)
Manageengine_network_configuration_managerZohocorp12.5-build125664 (including)12.5-build125664 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126000 (including)12.6-build126000 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126001 (including)12.6-build126001 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126100 (including)12.6-build126100 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126101 (including)12.6-build126101 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126102 (including)12.6-build126102 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126103 (including)12.6-build126103 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126113 (including)12.6-build126113 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126114 (including)12.6-build126114 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126115 (including)12.6-build126115 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126116 (including)12.6-build126116 (including)
Manageengine_network_configuration_managerZohocorp12.6-build126117 (including)12.6-build126117 (including)
Manageengine_opmanagerZohocorp12.5-build125450 (including)12.5-build125450 (including)
Manageengine_opmanagerZohocorp12.5-build125451 (including)12.5-build125451 (including)
Manageengine_opmanagerZohocorp12.5-build125452 (including)12.5-build125452 (including)
Manageengine_opmanagerZohocorp12.5-build125453 (including)12.5-build125453 (including)
Manageengine_opmanagerZohocorp12.5-build125455 (including)12.5-build125455 (including)
Manageengine_opmanagerZohocorp12.5-build125456 (including)12.5-build125456 (including)
Manageengine_opmanagerZohocorp12.5-build125664 (including)12.5-build125664 (including)
Manageengine_opmanagerZohocorp12.6-build126000 (including)12.6-build126000 (including)
Manageengine_opmanagerZohocorp12.6-build126001 (including)12.6-build126001 (including)
Manageengine_opmanagerZohocorp12.6-build126100 (including)12.6-build126100 (including)
Manageengine_opmanagerZohocorp12.6-build126101 (including)12.6-build126101 (including)
Manageengine_opmanagerZohocorp12.6-build126102 (including)12.6-build126102 (including)
Manageengine_opmanagerZohocorp12.6-build126103 (including)12.6-build126103 (including)
Manageengine_opmanagerZohocorp12.6-build126113 (including)12.6-build126113 (including)
Manageengine_opmanagerZohocorp12.6-build126114 (including)12.6-build126114 (including)
Manageengine_opmanagerZohocorp12.6-build126115 (including)12.6-build126115 (including)
Manageengine_opmanagerZohocorp12.6-build126116 (including)12.6-build126116 (including)
Manageengine_opmanagerZohocorp12.6-build126117 (including)12.6-build126117 (including)
Manageengine_opmanager_mspZohocorp12.5-build125450 (including)12.5-build125450 (including)
Manageengine_opmanager_mspZohocorp12.5-build125656 (including)12.5-build125656 (including)
Manageengine_opmanager_mspZohocorp12.5-build125664 (including)12.5-build125664 (including)
Manageengine_opmanager_mspZohocorp12.6-build126000 (including)12.6-build126000 (including)
Manageengine_opmanager_mspZohocorp12.6-build126001 (including)12.6-build126001 (including)
Manageengine_opmanager_mspZohocorp12.6-build126100 (including)12.6-build126100 (including)
Manageengine_opmanager_mspZohocorp12.6-build126103 (including)12.6-build126103 (including)
Manageengine_opmanager_mspZohocorp12.6-build126113 (including)12.6-build126113 (including)
Manageengine_opmanager_mspZohocorp12.6-build126117 (including)12.6-build126117 (including)
Manageengine_opmanager_plusZohocorp12.5-build125450 (including)12.5-build125450 (including)
Manageengine_opmanager_plusZohocorp12.5-build125656 (including)12.5-build125656 (including)
Manageengine_opmanager_plusZohocorp12.5-build125664 (including)12.5-build125664 (including)
Manageengine_opmanager_plusZohocorp12.6-build126000 (including)12.6-build126000 (including)
Manageengine_opmanager_plusZohocorp12.6-build126001 (including)12.6-build126001 (including)
Manageengine_opmanager_plusZohocorp12.6-build126100 (including)12.6-build126100 (including)
Manageengine_opmanager_plusZohocorp12.6-build126103 (including)12.6-build126103 (including)
Manageengine_opmanager_plusZohocorp12.6-build126113 (including)12.6-build126113 (including)
Manageengine_opmanager_plusZohocorp12.6-build126117 (including)12.6-build126117 (including)
Manageengine_oputilsZohocorp12.5-build125450 (including)12.5-build125450 (including)
Manageengine_oputilsZohocorp12.5-build125451 (including)12.5-build125451 (including)
Manageengine_oputilsZohocorp12.5-build125452 (including)12.5-build125452 (including)
Manageengine_oputilsZohocorp12.5-build125453 (including)12.5-build125453 (including)
Manageengine_oputilsZohocorp12.5-build125455 (including)12.5-build125455 (including)
Manageengine_oputilsZohocorp12.5-build125456 (including)12.5-build125456 (including)
Manageengine_oputilsZohocorp12.5-build125664 (including)12.5-build125664 (including)
Manageengine_oputilsZohocorp12.6-build126000 (including)12.6-build126000 (including)
Manageengine_oputilsZohocorp12.6-build126001 (including)12.6-build126001 (including)
Manageengine_oputilsZohocorp12.6-build126100 (including)12.6-build126100 (including)
Manageengine_oputilsZohocorp12.6-build126101 (including)12.6-build126101 (including)
Manageengine_oputilsZohocorp12.6-build126102 (including)12.6-build126102 (including)
Manageengine_oputilsZohocorp12.6-build126103 (including)12.6-build126103 (including)
Manageengine_oputilsZohocorp12.6-build126113 (including)12.6-build126113 (including)
Manageengine_oputilsZohocorp12.6-build126114 (including)12.6-build126114 (including)
Manageengine_oputilsZohocorp12.6-build126115 (including)12.6-build126115 (including)
Manageengine_oputilsZohocorp12.6-build126116 (including)12.6-build126116 (including)
Manageengine_oputilsZohocorp12.6-build126117 (including)12.6-build126117 (including)

References