# Security Updates - CVE-2021-125437 ## SQL injection vulnerability in support diagnostics module. | Vulnerability Details | | |---|---| | Severity | **High** | | Reported | Aug 30, 2021 | | Reported by | Hồng Dương Trần | | Fixed | 3rd September, 2021 | | Affected Builds | From version 125140 | | Fixed in | Build 125437 and 125453 | | Overview | SQL injection vulnerability in support diagnostics module. | | **Recommended Fix** | **→ For builds versions 125436 and below please upgrade to [OpManager Nexus Version 12.5.437.](https://www.manageengine.com/it-operations-management/service-packs.html)** | ## Description An SQL injection vulnerability was noticed from OpManager Nexus versions 125140. The SQL injection was allowed via the pollingObject parameter of the getDataCollectionFailureReason API. We strongly recommend you to [upgrade OpManager Nexus to version 125437](https://www.manageengine.com/it-operations-management/service-packs.html) or higher to resolve this vulnerability issue. ### Source and Acknowledgements Find out more about CVE-2021-125437 from the [CVE dictionary](https://nvd.nist.gov/vuln/detail/CVE-2021-125437). ## Need Help? For clarification or corrections please contact our [support team](https://www.manageengine.com/it-operations-management/support.html) or email us at [itom-upgrades@manageengine.com](mailto:itom-upgrades@manageengine.com).