Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and...
Vulnerability Description
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in a Delete operation to the APMBVHandler servlet or (2) query parameter in a compare operation to the DataComparisonServlet servlet.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-7868
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/71002
- http://seclists.org/fulldisclosure/2014/Nov/21
- https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_opmanager_socialit_it360.txt
- http://www.securityfocus.com/archive/1/533946/100/0/threaded
- https://support.zoho.com/portal/manageengine/helpcenter/articles/sql-injection-vulnerability-fix
- http://packetstormsecurity.com/files/129037/ManageEngine-OpManager-Social-IT-Plus-IT360-File-Upload-SQL-Injection.html
More from zohocorp
View All →Affected Vendor
zohocorp
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.