PT-2014-8319 · Zoho · Zoho Manageengine Opmanager+2
Published
2014-12-04
·
Updated
2019-07-15
·
CVE-2014-7867
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ZOHO ManageEngine OpManager versions 11.3 through 11.4
IT360 versions 10.3 through 10.4
Social IT Plus version 11.0
Description
A SQL injection issue exists in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet, allowing remote attackers or remote authenticated users to execute arbitrary SQL commands via the
probeName parameter.Recommendations
For ZOHO ManageEngine OpManager versions 11.3 through 11.4, consider restricting access to the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet until a fix is available.
For IT360 versions 10.3 through 10.4, avoid using the
probeName parameter in the affected servlet to minimize the risk of exploitation.
For Social IT Plus version 11.0, restrict access to the vulnerable servlet to prevent potential SQL injection attacks.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
It360
Social It Plus
Zoho Manageengine Opmanager