First published: Mon Jan 13 2020(Updated: )
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Eventlog Analyzer | >=7.0<=9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6038 is a database Information Disclosure Vulnerability in Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002.
CVE-2014-6038 has a severity rating of 7.5 (High).
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 are affected by CVE-2014-6038.
To fix CVE-2014-6038, you need to upgrade to EventLog Analyzer 10.0 Build 10000.
Yes, you can find references for CVE-2014-6038 at the following links: [http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html](http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html), [http://seclists.org/fulldisclosure/2014/Nov/12](http://seclists.org/fulldisclosure/2014/Nov/12), [http://www.securityfocus.com/bid/70959](http://www.securityfocus.com/bid/70959).