CVE-2024-6748: SQL Injection
Published Jul 29, 2024
·Updated
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.
Affected Software
4 affected components
Zohocorp ManageEngine OpManager<=128317
ZohoCorp Manageengine Opmanager Plus<=128317
Zohocorp Manageengine Opmanager Msp<=128317
Zohocorp ManageEngine RMM<=128317
Event History
Jul 29, 2024
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-6748?
CVE-2024-6748 is classified as a high severity vulnerability due to the potential for authenticated SQL injection.
2
How do I fix CVE-2024-6748?
To fix CVE-2024-6748, upgrade to ManageEngine OpManager, OpManager Plus, OpManager MSP, or RMM versions above 128317.
3
Who is affected by CVE-2024-6748?
CVE-2024-6748 affects users of ManageEngine OpManager, OpManager Plus, OpManager MSP, and RMM versions 128317 and below.
4
What is the impact of CVE-2024-6748?
The impact of CVE-2024-6748 includes the potential for unauthorized database access through SQL injection.
5
Is CVE-2024-6748 an authenticated vulnerability?
Yes, CVE-2024-6748 requires authentication to exploit the SQL injection vulnerability.