CVE-2024-5487: SQL Injection
Published Aug 12, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.
Affected Software
3 affected components
ZohoCorp ManageEngine ADAudit Plus<8.1
ZohoCorp ManageEngine ADAudit Plus=8.1
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
Event History
Aug 12, 2024
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5487?
CVE-2024-5487 has been classified as a high severity vulnerability due to the potential for unauthorized data access through SQL injection.
2
How do I fix CVE-2024-5487?
To remediate CVE-2024-5487, upgrade to Zoho ManageEngine ADAudit Plus version 8110 or later.
3
What versions are affected by CVE-2024-5487?
CVE-2024-5487 affects all versions of Zoho ManageEngine ADAudit Plus below version 8110.
4
What type of attack does CVE-2024-5487 allow?
CVE-2024-5487 allows authenticated SQL Injection attacks through the attack surface analyzer's export option.
5
Is there a workaround for CVE-2024-5487?
There are no officially recommended workarounds for CVE-2024-5487; upgrading the software is the advised action.