Vulnerability record · CVE-2021-3287 · published 22 April 2021
CVE-2021-3287: Zoho ManageEngine OpManager unauthenticated deserialization RCE
Zohocorp · Manageengine Opmanager
Zoho ManageEngine OpManager before 12.5.329 contains a Java deserialization flaw that can be triggered without authentication, allowing remote code execution. The root cause is a general bypass in the deserialization class, and the flaw is rated critical with a CVSS 3.1 score of 9.8.
Description
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-accessible remote code execution with a CVSS score of 9.8 and public exploit code makes this a critical risk.
What it is
Zoho ManageEngine OpManager before 12.5.329 contains a Java deserialization flaw that can be triggered without authentication, allowing remote code execution. The root cause is a general bypass in the deserialization class, and the flaw is rated critical with a CVSS 3.1 score of 9.8.
Impact
An unauthenticated attacker can execute arbitrary code on the affected OpManager server, leading to full compromise of the application and potentially the underlying host.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges or user interaction required (PR:N, UI:N), so it can be triggered directly over the network against the affected service.
Exploitation
The record is not listed in CISA KEV, but public exploit code is referenced (Packet Storm), and EPSS estimates a 30-day exploitation probability of about 51% (98.9th percentile).
What to do
- Upgrade ManageEngine OpManager to version 12.5.329 or later as documented in the vendor release notes.
- If immediate patching is not possible, restrict network access to the OpManager service to trusted management networks only.
- Monitor vendor advisories for any additional hotfixes or configuration guidance related to the deserialization issue.
- Review and harden Java deserialization usage in any custom integrations or extensions that interact with OpManager.
Detection
- Monitor network traffic and application logs for unexpected serialized Java objects or deserialization errors targeting OpManager endpoints.
- Alert on suspicious child processes spawned by the OpManager service, such as command shells or scripting interpreters.
- Use the public exploit reference to build signatures or behavioral detections for the SumPDU Java deserialization vector.
- Track outbound connections from the OpManager host to unknown external addresses that may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164231/ManageEngine-OpManager-SumPDU-Java-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125329 | Release NotesVendor Advisory |
| http://packetstormsecurity.com/files/164231/ManageEngine-OpManager-SumPDU-Java-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html#125329 | Release NotesVendor Advisory |
Track CVE-2021-3287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.