# List of security vulnerabilities fixed in OpManager Nexus This page contains a list of all security vulnerabilities fixed in OpManager Nexus along with its CVE id and fixed build number. Go to [ManageEngine's Security Response Center](https://www.manageengine.com/manageengine-security-response-center.html) to report vulnerabilities on ManageEngine products. | CVE / ZVE ID | Synopsis | Severity | Fixed in version | Link to latest build | |---|---|---|---|---| | [ZVE-2026-3290](https://www.manageengine.com/itom/advisory/zve-2026-3290.html) | An unauthenticated TCP relay and session shadowing was identified in the SparkGateway module which is used in RDP and Terminal access. This is now fixed. | Medium | 128736 / 128669 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [ZVE-2026-3318](https://www.manageengine.com/manageengine/itom/advisory/zve-2026-3318.html) | An Authenticated Insecure Direct Object Reference (IDOR)vulnerability was identified in certain Load Balancer components. This issue has now been fixed. | Medium | 128736 /128669 /129103 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2024-5466](https://www.manageengine.com/itom/advisory/cve-2024-5466.html) | OpManager: A Remote Code Execution (RCE) vulnerability could be exploited by users with 'Write' access to the 'Deploy Agent' action in the UI. This has been fixed now. [Reported by Daniel Santos] | High | 128330 / 128320 / 128188 / 128268 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2024-6748](https://www.manageengine.com/itom/advisory/cve-2024-6748.html) | OpManager: The SQL injection vulnerability identified in the URL Monitoring has now been fixed. [Reported by: CrisprXiang, Cokebeer, and LFY]. | High | 128318 / 128186 / 128267 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2023-47211](https://www.manageengine.com/itom/advisory/cve-2023-47211.html) | Earlier, path traversal vulnerability was detected for MIB browser. This issue has now been fixed by implementing path sanitization. | High | 127260 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [ZVE-2023-0284](https://www.manageengine.com/itom/advisory/zve-2023-0284.html) | OpManager : The Stored XSS vulnerability issues, that lead to JS injection, and were identified in the URL Monitors, have been fixed now. (Reported by Ranjit Pahan). | Medium | 126279 / 126155 / 126263 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2022-43473](https://www.manageengine.com/itom/advisory/cve-2022-43473.html) | OpManager : Previously, there was an XML External Entity (XXE) vulnerability in UCS module. It has been fixed now.(Reported by Cisco Talos-Marcin Noga) | Medium | 126141 / 126154/ 126169 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2022-37024](https://www.manageengine.com/itom/advisory/cve-2022-37024.html) | Earlier, there was a Remote Code Execution (RCE) vulnerability in IPv6 address management reported by an anonymous working with Trend Micro Zero Day Initiative. This has been fixed now. | High | 126120 / 126105 / 126003 / 125658 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2022-38772](https://www.manageengine.com/itom/advisory/cve-2022-38772.html) | Earlier, there was a Remote Code Execution (RCE) vulnerability in IPv4 address management reported by an anonymous working with Trend Micro Zero Day Initiative. This has been fixed now. | High | 126120 / 126105 / 126003 / 125658 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2022-36923](https://www.manageengine.com/itom/advisory/cve-2022-36923.html) | A vulnerability resulted in unauthenticated access of the user API key. This issue has been fixed now. (Reported by Anonymous working with Trend Micro Zero Day Initiative) | Critical | 126118 / 126104 / 126002 / 125657 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2022-35404](https://www.manageengine.com/itom/advisory/cve-2022-35404.html) | Unauthorized creation of files lead to high resource consumption. This has been fixed now.(Reported by Tenable) | Medium | 125639/ 125655/ 126101 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2022-29535](https://www.manageengine.com/it-operations-management/security-updates/cve-2022-29535.html) | The SQL injection vulnerability issues identified in a few default reports have been fixed now. (Reported by Anh Vu) | High | 125604 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2022-27908](https://www.manageengine.com/it-operations-management/security-updates/cve-2022-27908.html) | SQL vulnerability injection noticed in Inventory Reports module | High | 125588/125603 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2021-40493](https://www.manageengine.com/it-operations-management/security-updates/cve-2021-40493.html) | SQL vulnerability injection noticed in support diagnostics module | High | 125437/125453 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2021-3287](https://www.manageengine.com/it-operations-management/security-updates/cve-2021-3287.html) | Unauthenticated Remote Code Execution (RCE) vulnerability due to general bypass for the deserialization class. | Critical | 125220/125314 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2020-12116](https://www.manageengine.com/network-monitoring/security-updates/cve-2020-12116.html) | Path Traversal vulnerability | High | 124196/125125 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2019-15106](https://www.manageengine.com/it-operations-management/security-updates/cve-2019-15106.html) | User login bypass vulnerability in APM plugin | High | 124062/124070 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | Internal | An operator user could access some restricted folders by bypassing the session. | High | 123241 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) | | [CVE-2018-19403](https://www.manageengine.com/it-operations-management/security-updates/cve-2018-19403.html) | Unauthenticated Remote Code Execution (RCE) vulnerability | High | 123231 | [Download](https://www.manageengine.com/it-operations-management/service-packs.html) |