CVE-2017-16542: SQL Injection
Published Nov 5, 2017
·Updated
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
Affected Software
1 affected component
ZohoCorp ManageEngine Applications Manager=13.0
Event History
Nov 5, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16542?
CVE-2017-16542 has a moderate severity rating due to its potential for post-authentication SQL injection.
2
How do I fix CVE-2017-16542?
To fix CVE-2017-16542, upgrade to Zoho ManageEngine Applications Manager version 13 build 13500 or later.
3
What is the impact of CVE-2017-16542?
The impact of CVE-2017-16542 could allow attackers to execute arbitrary SQL commands on the database.
4
Which versions of Zoho ManageEngine Applications Manager are affected by CVE-2017-16542?
CVE-2017-16542 affects Zoho ManageEngine Applications Manager version 13.0 before build 13500.
5
How does the CVE-2017-16542 vulnerability occur?
CVE-2017-16542 occurs due to insufficient input validation in the name parameter during an insert operation via POST requests.