First published: Tue Oct 06 2020(Updated: )
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Applications Manager | =14.7 | |
ManageEngine Applications Manager | =14.7 | |
ManageEngine Applications Manager | =14.7-build14700 | |
ManageEngine Applications Manager | =14.7-build14710 | |
ManageEngine Applications Manager | =14.7-build14720 | |
ManageEngine Applications Manager | =14.7-build14730 | |
ManageEngine Applications Manager | =14.7-build14740 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16267 is a vulnerability that allows an authenticated SQL Injection in Zoho ManageEngine Applications Manager version 14740 and prior.
The severity of CVE-2020-16267 is high with a severity value of 8.8.
CVE-2020-16267 affects Zoho ManageEngine Applications Manager version 14740 and prior, allowing an authenticated SQL Injection.
To fix CVE-2020-16267, update Zoho ManageEngine Applications Manager to version 14.7-build14750 or later.
More information about CVE-2020-16267 can be found at the following references provided by ManageEngine: [Reference 1](https://www.manageengine.com), [Reference 2](https://www.manageengine.com/products/applications_manager/issues.html#v14750), [Reference 3](https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2020-16267.html).