CVE-2020-15927: SQL Injection
Published Oct 6, 2020
·Updated
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
Affected Software
7 affected components
ZohoCorp ManageEngine Applications Manager=14.7
ZohoCorp ManageEngine Applications Manager=14.7
ZohoCorp ManageEngine Applications Manager=14.7-build14700
ZohoCorp ManageEngine Applications Manager=14.7-build14710
ZohoCorp ManageEngine Applications Manager=14.7-build14720
ZohoCorp ManageEngine Applications Manager=14.7-build14730
ZohoCorp ManageEngine Applications Manager=14.7-build14740
Event History
Oct 6, 2020
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15927?
CVE-2020-15927 is a vulnerability in Zoho ManageEngine Applications Manager that allows an authenticated SQL Injection via a crafted jsp request in the SAP module.
2
What is the severity of CVE-2020-15927?
CVE-2020-15927 has a severity rating of 8.8 (high).
3
How does CVE-2020-15927 affect Zoho ManageEngine Applications Manager?
CVE-2020-15927 affects Zoho ManageEngine Applications Manager versions 14.7 and prior.
4
How can I fix CVE-2020-15927?
To fix CVE-2020-15927, it is recommended to update Zoho ManageEngine Applications Manager to version 14.7-build14750 or later.
5
Where can I find more information about CVE-2020-15927?
You can find more information about CVE-2020-15927 on the ManageEngine website.