PT-2020-14484 · Zoho · Zoho Manageengine Applications Manager

Vu Van Tien

·

Published

2020-10-01

·

Updated

2020-10-13

·

CVE-2020-15533

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Application Manager versions prior to 14684 Zoho ManageEngine Application Manager versions 14689 through 14750
Description The AlarmEscalation module in Zoho ManageEngine Application Manager is vulnerable to an unauthenticated SQL Injection attack.
Recommendations For versions prior to 14684, update to a version after 14684 to resolve the issue. For versions 14689 through 14750, update to a version after 14750 to resolve the issue. As a temporary workaround, consider disabling the AlarmEscalation module until a patch is available.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15533

Affected Products

Zoho Manageengine Applications Manager