PT-2015-3935 · Zoho · Zoho Manageengine Opmanager+1

Published

2015-02-04

·

Updated

2018-10-09

·

CVE-2014-7864

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ZOHO ManageEngine OpManager versions 8 through 11.5 build 11400 ZOHO ManageEngine IT360 version 10.5 and earlier
Description The issue allows remote attackers and remote authenticated users to execute arbitrary SQL commands. This is achieved via the customerName or serverRole parameter in a standbyUpdateInCentral operation to the "servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet" endpoint.
Recommendations For ZOHO ManageEngine OpManager versions 8 through 11.5 build 11400, avoid using the customerName and serverRole parameters in the affected servlet until a fix is available. For ZOHO ManageEngine IT360 version 10.5 and earlier, restrict access to the FailOverHelperServlet to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7864

Affected Products

Zoho Manageengine It360
Zoho Manageengine Opmanager