PT-2019-12476 · Zoho · Zoho Manageengine Firewall Analyzer

Publicado

2019-05-02

·

Atualizado

2019-05-03

·

CVE-2019-11678

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Firewall Analyzer versions prior to 12.3 Build 123218
Description The issue concerns the "default reports" feature, which is susceptible to SQL Injection.
Recommendations For versions prior to 12.3 Build 123218, update to version 12.3 Build 123218 or later to resolve the issue.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11678

Produtos afetados

Zoho Manageengine Firewall Analyzer