First published: Mon Jan 13 2020(Updated: )
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Eventlog Analyzer | >=7.0<=9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2014-6039.
The severity of CVE-2014-6039 is high with a severity value of 7.5.
The affected software is ManageEngine EventLog Analyzer version 7 through 9.9 build 9002.
To fix this vulnerability, you need to update to version 10 Build 10000 of ManageEngine EventLog Analyzer.
Yes, there are references available for this vulnerability. You can find them at the following links: [1](http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html), [2](http://seclists.org/fulldisclosure/2014/Nov/12), [3](http://www.securityfocus.com/bid/70960).