PT-2015-3935 · Zoho · Zoho Manageengine Opmanager+1

Publicado

2015-02-04

·

Atualizado

2018-10-09

·

CVE-2014-7864

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZOHO ManageEngine OpManager versions 8 through 11.5 build 11400 ZOHO ManageEngine IT360 version 10.5 and earlier
Description The issue allows remote attackers and remote authenticated users to execute arbitrary SQL commands. This is achieved via the customerName or serverRole parameter in a standbyUpdateInCentral operation to the "servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet" endpoint.
Recommendations For ZOHO ManageEngine OpManager versions 8 through 11.5 build 11400, avoid using the customerName and serverRole parameters in the affected servlet until a fix is available. For ZOHO ManageEngine IT360 version 10.5 and earlier, restrict access to the FailOverHelperServlet to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7864

Produtos afetados

Zoho Manageengine It360
Zoho Manageengine Opmanager