Fix available for unauthenticated blind SQL injection vulnerability issue. Apply the latest service pack.

Fix available for unauthenticated blind SQL injection vulnerability issue. Apply the latest service pack.

This is a security advisory for OpManager customers using versions 123056 or earlier. We recommend that you  upgrade to the latest version of  OpManager, 123057, to fix the security vulnerability described below.

Description: OpManager contained a vulnerability through which it was possible to upload files using an unauthenticated servlet. This was identified and disclosed by Digital Defense, a provider of security risk assessment solutions. For details, please refer to the public disclosure published on January 30th.


Severity: Very high.


Affected users: OpManager customers using version 123056 and lower.


Background:
Digital Defense responsibly disclosed the vulnerability to ManageEngine in November of 2017. Shortly  afterwardour security and development teams touched base with Digital Defense to gather more information. We accord the highest priority to fixing vulnerabilities, and this particular vulnerability was addressed on January 2nd with an update to OpManager (123057). Customers using this version and above already have protection from the disclosed vulnerability.

Next step: Download the upgrade pack from https://www.manageengine.com/network-monitoring/service-packs.html and immediately upgrade to the latest version (123057). Please read the upgrade instructions carefully before beginning the upgrade. For assistance, write to support@opmanager.com or call us toll-free at +1.888.720.9500.


Important note : As always, make a copy of the entire OpManager installation folder before applying the upgrade and keep the copy in a separate location. If anything goes wrong during the upgrade, you'll have this copy as a backup, which will keep all your settings intact. If you are using an MS SQL server as a backend database, take a back up of the OpManager database before upgrading. Once the upgrade is successfully completed, remember to delete the backup.

We offer our sincerest apologies for any inconvenience this may have caused.

Regards,
Bharani
OpManager Team




                New to ADManager Plus?

                  New to ADSelfService Plus?