Impact
ZohoCorp ManageEngine OpManager and Firewall Analyzer releases 12.8.669 and earlier are vulnerable to a SQL Injection flaw in the Rule Management Search Reports functionality. This flaw allows malicious input to be embedded into a database query, potentially enabling an attacker to extract, modify, or delete data stored in the application database. The vulnerability is classified under CWE‑89 and carries a CVSS score of 8.8, indicating a high severity exposure.
Affected Systems
The affected products are ZohoCorp ManageEngine OpManager and ZohoCorp ManageEngine Firewall Analyzer, specifically any installation running version 12.8.669 or older.
Risk and Exploitability
The CVSS base score of 8.8 reflects a large impact if exploited. Although EPSS information is not available, the lack of a KEV listing suggests the vulnerability has not been widely exploited in the wild yet, but the high score indicates it still poses a significant risk. The likely attack vector is through the web interface that provides Rule Management Search Reports, and it probably requires authenticated access with sufficient permissions to create or query reports. An attacker who can submit crafted input would be able to direct the database to return arbitrarily selected data or perform destructive operations.
OpenCVE Enrichment