CVE-2024-36514: SQL Injection
Published Aug 23, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.
Affected Software
1 affected component
ZohoCorp ManageEngine ADAudit Plus<8.0
Event History
Aug 23, 2024
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36514?
CVE-2024-36514 is considered a high-severity vulnerability due to the potential for authenticated SQL injection.
2
How do I fix CVE-2024-36514?
To fix CVE-2024-36514, upgrade ManageEngine ADAudit Plus to version 8000 or later.
3
What versions of ManageEngine ADAudit Plus are affected by CVE-2024-36514?
CVE-2024-36514 affects all versions of ManageEngine ADAudit Plus below 8000.
4
What type of vulnerability is CVE-2024-36514?
CVE-2024-36514 is an authenticated SQL injection vulnerability.
5
What could an attacker achieve by exploiting CVE-2024-36514?
An attacker exploiting CVE-2024-36514 could potentially access and manipulate the database, leading to data breaches.