PT-2014-8319 · Zoho · Zoho Manageengine Opmanager+2

Published

2014-12-04

·

Updated

2019-07-15

·

CVE-2014-7867

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZOHO ManageEngine OpManager versions 11.3 through 11.4 IT360 versions 10.3 through 10.4 Social IT Plus version 11.0
Description A SQL injection issue exists in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet, allowing remote attackers or remote authenticated users to execute arbitrary SQL commands via the probeName parameter.
Recommendations For ZOHO ManageEngine OpManager versions 11.3 through 11.4, consider restricting access to the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet until a fix is available. For IT360 versions 10.3 through 10.4, avoid using the probeName parameter in the affected servlet to minimize the risk of exploitation. For Social IT Plus version 11.0, restrict access to the vulnerable servlet to prevent potential SQL injection attacks.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7867

Affected Products

It360
Social It Plus
Zoho Manageengine Opmanager