CVE-2017-16849: SQL Injection
Published Nov 16, 2017
·Updated
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
Affected Software
1 affected component
ZohoCorp ManageEngine Applications Manager=13.0
Event History
Nov 16, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Zoho ManageEngine Applications Manager?
The vulnerability ID for Zoho ManageEngine Applications Manager is CVE-2017-16849.
2
What is the severity rating of CVE-2017-16849?
The severity rating of CVE-2017-16849 is critical with a severity value of 9.8.
3
How does CVE-2017-16849 affect Zoho ManageEngine Applications Manager?
CVE-2017-16849 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter in Zoho ManageEngine Applications Manager 13 before build 13530.
4
What is the affected version of Zoho ManageEngine Applications Manager?
The affected version of Zoho ManageEngine Applications Manager is version 13.0.
5
How to fix CVE-2017-16849?
To fix CVE-2017-16849, update Zoho ManageEngine Applications Manager to build 13530 or later.