CVE-2019-12196: SQL Injection
A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12196?
The severity of CVE-2019-12196 is critical with a CVSS score of 9.8.
How does the SQL injection vulnerability in Zoho ManageEngine NetFlow Analyzer 12.3 work?
The SQL injection vulnerability in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands by manipulating the DeviceID parameter.
Which version of Zoho ManageEngine NetFlow Analyzer is affected by CVE-2019-12196?
Zoho ManageEngine NetFlow Analyzer version 12.3 is affected by CVE-2019-12196.
What can an attacker do with the SQL injection vulnerability in Zoho ManageEngine NetFlow Analyzer 12.3?
An attacker can execute arbitrary SQL commands, potentially gaining unauthorized access to the application's database.
How can I mitigate the SQL injection vulnerability in Zoho ManageEngine NetFlow Analyzer 12.3?
To mitigate the SQL injection vulnerability, it is recommended to update to a patched version of Zoho ManageEngine NetFlow Analyzer.