CVE-2014-6043: Medium severity manageengine eventlog analyzer vulnerability
Published Sep 11, 2014
·Updated
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.
Affected Software
2 affected components
ZohoCorp Manageengine Eventlog Analyzer=8.2-8020
ZohoCorp Manageengine Eventlog Analyzer=9.0-9002
Event History
Sep 11, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6043?
CVE-2014-6043 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2014-6043?
To fix CVE-2014-6043, you should upgrade to Build 10000 or later of ZOHO ManageEngine EventLog Analyzer.
3
Who is affected by CVE-2014-6043?
CVE-2014-6043 affects users of ZOHO ManageEngine EventLog Analyzer versions 8.2 build 8020 and 9.0 build 9002.
4
What type of vulnerability is CVE-2014-6043?
CVE-2014-6043 is an access control vulnerability that allows unauthorized access to the database browser.
5
Can CVE-2014-6043 be exploited remotely?
Yes, CVE-2014-6043 can be exploited by remote authenticated users through direct requests.