Skip to content

Commit

Permalink
Add a note about exploitable versions
Browse files Browse the repository at this point in the history
  • Loading branch information
zeroSteiner committed Sep 16, 2021
1 parent fd0f565 commit 4bccc05
Showing 1 changed file with 4 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,10 @@ def initialize(info = {})
commands in the context of the OpManager application (NT AUTHORITY\SYSTEM on Windows or root on Linux). This
vulnerability is also present in other products that are built on top of the OpManager application. This
vulnerability affects OpManager versions 12.1 - 12.5.328.
Automatic CVE selection only works for newer targets when the build number is present in the logon page. Due
to issues with the serialized payload this module is incompatible with versions prior to 12.3.238 despite them
technically being vulnerable.
},
'Author' => [
'Johannes Moritz', # Original Vulnerability Research
Expand Down

0 comments on commit 4bccc05

Please sign in to comment.