CVE-2024-5678: SQL Injection
Published Aug 1, 2024
·Updated
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
Affected Software
22 affected components
ZohoCorp ManageEngine Applications Manager<16.8
ZohoCorp ManageEngine Applications Manager=16.8
ZohoCorp ManageEngine Applications Manager=16.8-build16800
ZohoCorp ManageEngine Applications Manager=16.8-build16810
ZohoCorp ManageEngine Applications Manager=16.8-build16820
ZohoCorp ManageEngine Applications Manager=16.8-build16830
ZohoCorp ManageEngine Applications Manager=16.8-build16840
ZohoCorp ManageEngine Applications Manager=16.8-build16841
ZohoCorp ManageEngine Applications Manager=16.8-build16842
ZohoCorp ManageEngine Applications Manager=16.8-build16843
ZohoCorp ManageEngine Applications Manager=17.0
ZohoCorp ManageEngine Applications Manager=17.0-build170000
ZohoCorp ManageEngine Applications Manager=17.0-build170001
ZohoCorp ManageEngine Applications Manager=17.0-build170100
ZohoCorp ManageEngine Applications Manager=17.0-build170200
ZohoCorp ManageEngine Applications Manager=17.0-build170300
ZohoCorp ManageEngine Applications Manager=17.0-build170400
ZohoCorp ManageEngine Applications Manager=17.0-build170500
ZohoCorp ManageEngine Applications Manager=17.0-build170600
ZohoCorp ManageEngine Applications Manager=17.0-build170700
ZohoCorp ManageEngine Applications Manager=17.0-build170800
ZohoCorp ManageEngine Applications Manager=17.0-build170900
Event History
Aug 1, 2024
CVE Published
via MITRE·06:54 AM
Data Sourced
via MITRE·06:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-5678?
CVE-2024-5678 has been classified with a severity level that indicates a significant risk due to authenticated admin-only SQL Injection.
2
How do I fix CVE-2024-5678?
To mitigate CVE-2024-5678, upgrade your Zohocorp ManageEngine Applications Manager to a version higher than 17.0.
3
Which versions of Zohocorp ManageEngine Applications Manager are affected by CVE-2024-5678?
CVE-2024-5678 affects all versions up to and including 17.0, specifically those below 170900.
4
What type of attack does CVE-2024-5678 involve?
CVE-2024-5678 involves an authenticated admin-only SQL Injection vulnerability within the Create Monitor feature.
5
Is CVE-2024-5678 easy to exploit?
Exploitation of CVE-2024-5678 requires administrative access, making it less accessible to unauthorized users.