Impact
An XML Injection flaw exists in the Rule Tracking Compare Policies feature of ManageEngine OpManager and Firewall Analyzer. The vulnerability allows an attacker to inject crafted XML content, which could lead to remote code execution or allow the attacker to manipulate data within the application. The weakness is classified as CWE-91, indicating insufficient validation of XML input.
Affected Systems
The affected products are ZohoCorp ManageEngine Firewall Analyzer and ZohoCorp ManageEngine OpManager. Versions 12.8.709 and earlier are vulnerable; any deployment using those or older releases is at risk.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, but the lack of KEV listing suggests it is not a currently known exploited vulnerability. The likely attack vector is through authenticated or unauthenticated use of the web interface that exposes the Rule Tracking Compare Policies function. Exploitation would require the attacker to send malicious XML payloads to the target system.
OpenCVE Enrichment