PT-2015-7596 · Manageengine · Manageengine Opmanager

Xistence

·

Publicado

2015-10-09

·

Atualizado

2015-10-09

·

CVE-2015-7766

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ManageEngine OpManager versions 11.6, 11.5, and earlier
Description The issue allows remote administrators to bypass SQL query restrictions. This can be achieved by including a comment in the query to the "api/json/admin/SubmitQuery" API endpoint, such as using "INSERT/**/INTO" to bypass restrictions.
Recommendations For ManageEngine OpManager versions 11.6, 11.5, and earlier, consider restricting access to the "api/json/admin/SubmitQuery" API endpoint until a fix is available. As a temporary workaround, limit the ability of remote administrators to submit queries that could potentially bypass SQL query restrictions.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7766

Produtos afetados

Manageengine Opmanager