Vulnerability record · CVE-2021-41288 · published 30 September 2021
CVE-2021-41288: Zoho ManageEngine OpManager getReportData API SQL injection
Zohocorp · Manageengine Opmanager
Zoho ManageEngine OpManager build 125466 and below contains a SQL injection flaw in the getReportData API. Because the endpoint is network-reachable and requires no authentication, an unauthenticated attacker can inject SQL into backend queries, making this a critical pre-auth issue for any exposed instance.
Description
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus a very high EPSS score, makes this an urgent pre-auth SQL injection risk on internet-exposed instances.
What it is
Zoho ManageEngine OpManager build 125466 and below contains a SQL injection flaw in the getReportData API. Because the endpoint is network-reachable and requires no authentication, an unauthenticated attacker can inject SQL into backend queries, making this a critical pre-auth issue for any exposed instance.
Impact
An attacker can read, modify, or delete data in the underlying database and potentially execute database-level commands, depending on the DBMS privileges in use. Full compromise of confidentiality, integrity, and availability of the application data is possible.
Attack surface
Reached over the network via the getReportData API endpoint; the CVSS vector shows no privileges required and no user interaction, so the request can be sent directly by an unauthenticated attacker. Any OpManager instance with the API reachable from an untrusted network is exposed.
Exploitation
Not listed in CISA KEV and no public exploit references are included, but EPSS is very high (0.79553, 99.6th percentile), indicating strong likelihood of exploitation activity. The only references are vendor release notes, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Upgrade OpManager to build 125467 or later, which the vendor release notes identify as the fix.
- Restrict network access to the OpManager web/API interface to trusted management networks or VPN only.
- If immediate patching is not possible, place the instance behind a WAF or reverse proxy and block or tightly filter requests to the getReportData API.
- Run the OpManager database with least-privilege credentials so injected queries cannot reach unrelated schemas or perform administrative actions.
- Audit and rotate any credentials or data that may have been exposed through the database if compromise is suspected.
Detection
- Review web server and OpManager logs for requests to the getReportData API containing SQL metacharacters such as quotes, UNION, OR 1=1, or comment sequences.
- Alert on anomalous or high-volume API calls to getReportData from single source IPs or unusual geographies.
- Monitor database logs for unexpected queries, errors, or schema access originating from the OpManager application account.
- Baseline normal getReportData parameters and flag deviations in parameter length, encoding, or structure.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_125467 | Release NotesVendor Advisory |
| https://www.manageengine.com/network-monitoring/help/read-me-complete.html#build_125467 | Release NotesVendor Advisory |
Track CVE-2021-41288 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41288), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.