Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:SQL:INJ:OPMNGR-AGENT-SQL

Severity

High

Recommended

No

Category

HTTP

Keywords

ManageEngine OpManager AgentDetailsUtil agentKey SQL Injection

Release Date

2015/08/27

Update Number

2529

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: ManageEngine OpManager AgentDetailsUtil agentKey SQL Injection


An SQL injection vulnerability exists in ManageEngine OpManager. This vulnerability is due to insufficient validation of the agentKey parameter when processing requests sent to "com.manageengine.opmanager.servlet.AgentDetailsUtil". A remote attacker can exploit this vulnerability to inject and execute arbitrary SQL code on the affected system.

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out