PT-2020-14484 · Zoho · Zoho Manageengine Applications Manager
Vu Van Tien
·
Published
2020-10-01
·
Updated
2020-10-13
·
CVE-2020-15533
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Application Manager versions prior to 14684
Zoho ManageEngine Application Manager versions 14689 through 14750
Description
The AlarmEscalation module in Zoho ManageEngine Application Manager is vulnerable to an unauthenticated SQL Injection attack.
Recommendations
For versions prior to 14684, update to a version after 14684 to resolve the issue.
For versions 14689 through 14750, update to a version after 14750 to resolve the issue.
As a temporary workaround, consider disabling the AlarmEscalation module until a patch is available.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Applications Manager