{ "schema_version": "1.4.0", "id": "GHSA-hgc7-q3qg-xcgm", "modified": "2025-04-12T12:52:42Z", "published": "2022-05-17T04:04:50Z", "aliases": [ "CVE-2015-7765" ], "details": "ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of \"plugin\" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-7765" }, { "type": "WEB", "url": "https://support.zoho.com/portal/manageengine/helpcenter/articles/pgsql-submitquery-do-vulnerability" }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/38221" }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/133596/ManageEngine-OpManager-Remote-Code-Execution.html" }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2015/Sep/66" }, { "type": "WEB", "url": "http://www.rapid7.com/db/modules/exploit/windows/http/manage_engine_opmanager_rce" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2015-10-09T14:59:00Z" } }