Vulnerability Details CVE-2022-38772
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.404
EPSS Ranking 97.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-38772
-
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.5
-
cpe:2.3:a:zohocorp:manageengine_netflow_analyzer:12.6
-
cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.5
-
cpe:2.3:a:zohocorp:manageengine_network_configuration_manager:12.6
-
cpe:2.3:a:zohocorp:manageengine_opmanager:12.5
-
cpe:2.3:a:zohocorp:manageengine_opmanager:12.6
-
cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.5
-
cpe:2.3:a:zohocorp:manageengine_opmanager_msp:12.6
-
cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.5
-
cpe:2.3:a:zohocorp:manageengine_opmanager_plus:12.6
-
cpe:2.3:a:zohocorp:manageengine_oputils:12.5
-
cpe:2.3:a:zohocorp:manageengine_oputils:12.6