CVE-2024-36485: SQL Injection
Published Nov 4, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
Affected Software
5 affected components
ZohoCorp ManageEngine ADAudit Plus<8.1
ZohoCorp ManageEngine ADAudit Plus=8.1
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
ZohoCorp ManageEngine ADAudit Plus=8.1-8110
ZohoCorp ManageEngine ADAudit Plus=8.1-8120
Event History
Nov 4, 2024
CVE Published
via MITRE·11:13 AM
Data Sourced
via MITRE·11:13 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36485?
CVE-2024-36485 is classified as a high severity vulnerability due to its potential to allow SQL Injection attacks.
2
How do I fix CVE-2024-36485?
To fix CVE-2024-36485, upgrade your Zoho ManageEngine ADAudit Plus to version 8121 or later.
3
Which versions are affected by CVE-2024-36485?
CVE-2024-36485 affects all versions of Zoho ManageEngine ADAudit Plus prior to version 8121.
4
What type of vulnerability is CVE-2024-36485?
CVE-2024-36485 is a SQL Injection vulnerability found in the Technician reports option of the software.
5
Can CVE-2024-36485 be exploited remotely?
Yes, CVE-2024-36485 can be exploited remotely, allowing attackers to manipulate database queries.