Blind XML External Entity Vulnerability in ManageEngine OpManager
CVE-2022-43473
5.8MEDIUM
What is CVE-2022-43473?
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager. This flaw allows attackers to exploit the system by supplying a specially crafted XML file, leading to potential Server-Side Request Forgery (SSRF). It is crucial for users of affected versions to apply security measures to safeguard their systems against this vulnerability.
Affected Version(s)
OpManager 12.6.168