ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.
References
Configurations
Information
Published : 2015-10-09 07:59
Updated : 2015-10-09 10:42
NVD link : CVE-2015-7765
Mitre link : CVE-2015-7765
JSON object : View
CWE
Products Affected
zohocorp
- manageengine_opmanager