Vulnerability Details CVE-2021-40493
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.275
EPSS Ranking 96.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2021-40493
-
cpe:2.3:a:zohocorp:manageengine_opmanager:-
-
cpe:2.3:a:zohocorp:manageengine_opmanager:11.4
-
cpe:2.3:a:zohocorp:manageengine_opmanager:11.5
-
cpe:2.3:a:zohocorp:manageengine_opmanager:12.2
-
cpe:2.3:a:zohocorp:manageengine_opmanager:12.3
-
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4
-
cpe:2.3:a:zohocorp:manageengine_opmanager:12.4.179
-
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5
-
cpe:2.3:a:zohocorp:manageengine_opmanager:8