Impact
The vulnerability arises because an authentication check is missing when the Application Manager Plugin is enabled, allowing attackers to craft requests that bypass authentication and gain unauthorized access to the OpManager management interface. This flaw is classified as CWE-306, giving an adversary the ability to perform privileged actions such as modifying monitoring configurations or extracting sensitive data.
Affected Systems
Zohocorp’s ManageEngine OpManager, versions 12.8.710 and earlier, are impacted when the Application Manager Plugin is active. Any deployment of these versions with the plugin enabled is subject to the bypass, regardless of the underlying operating system. Upgrading to a version newer than 12.8.710 eliminates the issue.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, and while the EPSS score is not available, the absence of a KEV listing suggests no publicly known exploits yet. The likely attack vector is remote; an attacker who can reach the OpManager instance could trigger the bypass over HTTP or HTTPS without valid credentials, potentially enabling full system compromise.
OpenCVE Enrichment