First published: Thu Dec 04 2014(Updated: )
SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the probeName parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine OpManager MSP | =11.3 | |
ManageEngine OpManager MSP | =11.4 | |
ManageEngine Social IT Plus | =11.0 | |
ManageEngine IT360 | =10.3.0 | |
ManageEngine IT360 | =10.4 |
https://support.zoho.com/portal/manageengine/helpcenter/articles/sql-injection-vulnerability-fix
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7867 is classified as a medium severity SQL injection vulnerability.
To fix CVE-2014-7867, update your affected ManageEngine software to the latest version that addresses this vulnerability.
CVE-2014-7867 affects ManageEngine OpManager versions 11.3 and 11.4, IT360 versions 10.3 and 10.4, and Social IT Plus version 11.0.
Yes, CVE-2014-7867 can be exploited by remote attackers without authentication to execute arbitrary SQL commands.
The potential impacts of CVE-2014-7867 include unauthorized access to sensitive data and the ability to alter database content.