CVE-2024-36035: SQL Injection
Published Aug 12, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.
Affected Software
5 affected components
ZohoCorp ManageEngine ADAudit Plus<8.0
ZohoCorp ManageEngine ADAudit Plus=8.0
ZohoCorp ManageEngine ADAudit Plus=8.0-8000
ZohoCorp ManageEngine ADAudit Plus=8.0-8001
ZohoCorp ManageEngine ADAudit Plus=8.0-8002
Event History
Aug 12, 2024
CVE Published
via MITRE·07:19 AM
Data Sourced
via MITRE·07:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36035?
CVE-2024-36035 is classified as a medium severity vulnerability due to the risk of authenticated SQL injection.
2
How do I fix CVE-2024-36035?
To fix CVE-2024-36035, upgrade to ManageEngine ADAudit Plus version 8003 or later.
3
Who is affected by CVE-2024-36035?
CVE-2024-36035 affects users of ManageEngine ADAudit Plus versions prior to 8003.
4
What type of vulnerability is CVE-2024-36035?
CVE-2024-36035 is an authenticated SQL Injection vulnerability.
5
What can attackers do with CVE-2024-36035?
Attackers exploiting CVE-2024-36035 could potentially access and manipulate sensitive database information.