A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve
a malicious XML payload to trigger this vulnerability.
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Changed
Confidentiality Impact Low
Integrity Impact Low
Availability Impact Low
User Interaction Required
No CVSS v3.0
No CVSS v2
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Zohocorp |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
No data.
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: talos
Published: 2023-03-30T16:28:35.983Z
Updated: 2024-08-03T13:32:59.643Z
Reserved: 2022-12-05T20:53:36.058Z
Link: CVE-2022-43473
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-30T17:15:06.750
Modified: 2023-11-07T03:53:49.523
Link: CVE-2022-43473
Redhat
No data.