CVE-2020-35765: SQL Injection
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35765?
The severity of CVE-2020-35765 is high with a CVSS score of 8.8.
How does CVE-2020-35765 impact Zoho ManageEngine Applications Manager?
CVE-2020-35765 allows an authenticated SQL Injection vulnerability in Zoho ManageEngine Applications Manager versions 14.9 to exploit the 'doFilter' function in 'com.adventnet.appmanager.filter.UriCollector', specifically through the 'resourceid' parameter in 'showresource.do'.
Which versions of Zoho ManageEngine Applications Manager are affected by CVE-2020-35765?
Zoho ManageEngine Applications Manager versions 14.9 to 14.9-build14930 are affected by CVE-2020-35765.
How can I mitigate or fix CVE-2020-35765?
To mitigate CVE-2020-35765, it is recommended to upgrade Zoho ManageEngine Applications Manager to version 14.9-build15000 or apply the appropriate security update provided by ManageEngine.
Where can I find more information about CVE-2020-35765?
You can find more information about CVE-2020-35765 on the ManageEngine website.