PT-2014-8319 · Zoho · Zoho Manageengine Opmanager+2

Publicado

2014-12-04

·

Atualizado

2019-07-15

·

CVE-2014-7867

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZOHO ManageEngine OpManager versions 11.3 through 11.4 IT360 versions 10.3 through 10.4 Social IT Plus version 11.0
Description A SQL injection issue exists in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet, allowing remote attackers or remote authenticated users to execute arbitrary SQL commands via the probeName parameter.
Recommendations For ZOHO ManageEngine OpManager versions 11.3 through 11.4, consider restricting access to the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet until a fix is available. For IT360 versions 10.3 through 10.4, avoid using the probeName parameter in the affected servlet to minimize the risk of exploitation. For Social IT Plus version 11.0, restrict access to the vulnerable servlet to prevent potential SQL injection attacks.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7867

Produtos afetados

It360
Social It Plus
Zoho Manageengine Opmanager