Vulnerability record · CVE-2018-17243 · published 20 September 2018
CVE-2018-17243: Zoho ManageEngine OpManager Global Search SQL Injection
Zohocorp · Manageengine Opmanager
Global Search in Zoho ManageEngine OpManager before 12.3 123205 is vulnerable to SQL injection. The flaw is remotely reachable without authentication or user interaction, and the record gives no further detail on the vulnerable code path. Because OpManager is a network monitoring platform, a successful injection can expose or alter the data it stores.
Description
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and very high EPSS make this a top remediation priority despite the absence of KEV listing.
What it is
Global Search in Zoho ManageEngine OpManager before 12.3 123205 is vulnerable to SQL injection. The flaw is remotely reachable without authentication or user interaction, and the record gives no further detail on the vulnerable code path. Because OpManager is a network monitoring platform, a successful injection can expose or alter the data it stores.
Impact
An attacker can read, modify, or delete data in the backend database and potentially execute database-level operations. With a CVSS 3.0 score of 9.8 (C/I/A all High), full compromise of confidentiality, integrity, and availability is possible.
Attack surface
Reached over the network via the Global Search feature; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required. The record does not specify the exact request or parameter.
Exploitation
Not listed in CISA KEV and no public exploit reference is provided, but EPSS is 0.74435 (99.467th percentile), indicating a high modeled likelihood of exploitation activity. The only references are vendor release notes, so no confirmed in-the-wild exploitation is documented here.
What to do
- Upgrade OpManager to version 12.3 123205 or later, per the vendor release notes.
- If immediate patching is not possible, restrict network access to the OpManager web interface to trusted management networks only.
- Place the OpManager interface behind a reverse proxy or WAF with SQL injection filtering.
- Review database accounts used by OpManager and apply least privilege to limit injection impact.
- Audit logs for unexpected Global Search queries and database errors.
Detection
- Monitor web server and application logs for SQL metacharacters or UNION/boolean patterns in Global Search requests.
- Alert on database error messages or unusual query volume originating from the OpManager host.
- Baseline normal Global Search usage and flag anomalous query lengths or frequencies from single source IPs.
- Watch for outbound connections from the OpManager server to unexpected destinations that could indicate data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/network-monitoring/help/read-me.html | Release NotesVendor Advisory |
| https://www.manageengine.com/network-monitoring/help/read-me.html | Release NotesVendor Advisory |
Track CVE-2018-17243 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-17243), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.