CVE-2014-6038: Infoleak
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-6038?
CVE-2014-6038 is a database Information Disclosure Vulnerability in Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002.
How severe is CVE-2014-6038?
CVE-2014-6038 has a severity rating of 7.5 (High).
What software versions are affected by CVE-2014-6038?
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 are affected by CVE-2014-6038.
How can I fix CVE-2014-6038?
To fix CVE-2014-6038, you need to upgrade to EventLog Analyzer 10.0 Build 10000.
Are there any references for CVE-2014-6038?
Yes, you can find references for CVE-2014-6038 at the following links: [http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html](http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html), [http://seclists.org/fulldisclosure/2014/Nov/12](http://seclists.org/fulldisclosure/2014/Nov/12), [http://www.securityfocus.com/bid/70959](http://www.securityfocus.com/bid/70959).