vendor:
OpManager
by:
xistence
7,5
CVSS
HIGH
hardcoded credentials, SQL query protection bypass
798
CWE
Product Name: OpManager
Affected Version From: v11.5 and previous versions
Affected Version To: v11.5
Patch Exists: YES
Related CWE: N/A
CPE: a:manageengine:opmanager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
ManageEngine OpManager multiple vulnerabilities
ManageEngine OpManager ships with a default account 'IntegrationUser' with the password 'plugin'. This account is hidden from the user interface and will never show up in the user management. Also changing the password for this account is not possible by default. The account however is assigned Administrator privileges and logging in with this account is possible via the web interface. Any account that has access to the web interace can also access the PostgreSQL database. This means that any user with access to the web interface can access the database and gain access to the data stored in the database.
Mitigation:
Ensure that the default account is disabled and that the password is changed to a strong one.