CVE-2024-36517: SQL Injection
Published Aug 23, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.
Affected Software
1 affected component
ZohoCorp ManageEngine ADAudit Plus<8.0
Event History
Aug 23, 2024
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-36517?
CVE-2024-36517 has been classified as a high-severity vulnerability due to the potential for data manipulation through SQL injection.
2
How do I fix CVE-2024-36517?
To fix CVE-2024-36517, upgrade your ManageEngine ADAudit Plus to version 8000 or newer.
3
What types of attacks can CVE-2024-36517 enable?
CVE-2024-36517 can enable attackers to execute unauthorized SQL queries, potentially leading to data leakage or compromise.
4
Who is affected by CVE-2024-36517?
Any user running ManageEngine ADAudit Plus versions below 8000 is affected by CVE-2024-36517.
5
Is authentication required to exploit CVE-2024-36517?
Yes, exploitation of CVE-2024-36517 requires authenticated access to the alerts module of ADAudit Plus.