CVE-2020-16267: SQL Injection
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-16267?
CVE-2020-16267 is a vulnerability that allows an authenticated SQL Injection in Zoho ManageEngine Applications Manager version 14740 and prior.
What is the severity of CVE-2020-16267?
The severity of CVE-2020-16267 is high with a severity value of 8.8.
How does CVE-2020-16267 affect Zoho ManageEngine Applications Manager?
CVE-2020-16267 affects Zoho ManageEngine Applications Manager version 14740 and prior, allowing an authenticated SQL Injection.
How can I fix CVE-2020-16267?
To fix CVE-2020-16267, update Zoho ManageEngine Applications Manager to version 14.7-build14750 or later.
Where can I find more information about CVE-2020-16267?
More information about CVE-2020-16267 can be found at the following references provided by ManageEngine: [Reference 1](https://www.manageengine.com), [Reference 2](https://www.manageengine.com/products/applications_manager/issues.html#v14750), [Reference 3](https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2020-16267.html).