CVE-2024-5490: SQL Injection
Published Aug 23, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.
Affected Software
1 affected component
ZohoCorp ManageEngine ADAudit Plus<8.0
Event History
Aug 23, 2024
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5490?
CVE-2024-5490 is considered a critical vulnerability due to its potential for authenticated SQL injection.
2
How do I fix CVE-2024-5490?
To fix CVE-2024-5490, upgrade ManageEngine ADAudit Plus to version 8000 or later.
3
Which versions of ManageEngine ADAudit Plus are affected by CVE-2024-5490?
ManageEngine ADAudit Plus versions below 8000 are vulnerable to CVE-2024-5490.
4
What type of vulnerability is CVE-2024-5490?
CVE-2024-5490 is an authenticated SQL injection vulnerability.
5
What impacts does CVE-2024-5490 have on affected systems?
CVE-2024-5490 can allow attackers to manipulate database queries, potentially leading to unauthorized data access.