CVE-2024-5586: SQL Injection
Published Aug 23, 2024
·Updated
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
Affected Software
4 affected components
ZohoCorp ManageEngine ADAudit Plus<=8.0
ZohoCorp ManageEngine ADAudit Plus=8.1-8100
ZohoCorp ManageEngine ADAudit Plus=8.1-8110
ZohoCorp ManageEngine ADAudit Plus=8.1-8120
Event History
Aug 23, 2024
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5586?
CVE-2024-5586 is considered a critical vulnerability due to its potential for exploitation via authenticated SQL injection.
2
How do I fix CVE-2024-5586?
To fix CVE-2024-5586, you should upgrade your Zoho ManageEngine ADAudit Plus to version 8121 or later.
3
Which versions of Zoho ManageEngine ADAudit Plus are affected by CVE-2024-5586?
CVE-2024-5586 affects all versions of Zoho ManageEngine ADAudit Plus below 8121, including versions 8.1-8100, 8.1-8110, and 8.1-8120.
4
What type of attack does CVE-2024-5586 facilitate?
CVE-2024-5586 facilitates an authenticated SQL injection attack in the extranet lockouts report option.
5
Has CVE-2024-5586 been publicly disclosed?
Yes, CVE-2024-5586 has been publicly disclosed and details are available in security advisories related to the vulnerability.