First published: Thu Aug 01 2024(Updated: )
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Applications Manager | <16.8 | |
ManageEngine Applications Manager | =16.8 | |
ManageEngine Applications Manager | =16.8-build16800 | |
ManageEngine Applications Manager | =16.8-build16810 | |
ManageEngine Applications Manager | =16.8-build16820 | |
ManageEngine Applications Manager | =16.8-build16830 | |
ManageEngine Applications Manager | =16.8-build16840 | |
ManageEngine Applications Manager | =16.8-build16841 | |
ManageEngine Applications Manager | =16.8-build16842 | |
ManageEngine Applications Manager | =16.8-build16843 | |
ManageEngine Applications Manager | =17.0 | |
ManageEngine Applications Manager | =17.0-build170000 | |
ManageEngine Applications Manager | =17.0-build170001 | |
ManageEngine Applications Manager | =17.0-build170100 | |
ManageEngine Applications Manager | =17.0-build170200 | |
ManageEngine Applications Manager | =17.0-build170300 | |
ManageEngine Applications Manager | =17.0-build170400 | |
ManageEngine Applications Manager | =17.0-build170500 | |
ManageEngine Applications Manager | =17.0-build170600 | |
ManageEngine Applications Manager | =17.0-build170700 | |
ManageEngine Applications Manager | =17.0-build170800 | |
ManageEngine Applications Manager | =17.0-build170900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5678 has been classified with a severity level that indicates a significant risk due to authenticated admin-only SQL Injection.
To mitigate CVE-2024-5678, upgrade your Zohocorp ManageEngine Applications Manager to a version higher than 17.0.
CVE-2024-5678 affects all versions up to and including 17.0, specifically those below 170900.
CVE-2024-5678 involves an authenticated admin-only SQL Injection vulnerability within the Create Monitor feature.
Exploitation of CVE-2024-5678 requires administrative access, making it less accessible to unauthorized users.