Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_applications_manager | Zohocorp | * | 16.8 (excluding) |
Manageengine_applications_manager | Zohocorp | 16.8 (including) | 16.8 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16800 (including) | 16.8-build16800 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16810 (including) | 16.8-build16810 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16820 (including) | 16.8-build16820 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16830 (including) | 16.8-build16830 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16840 (including) | 16.8-build16840 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16841 (including) | 16.8-build16841 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16842 (including) | 16.8-build16842 (including) |
Manageengine_applications_manager | Zohocorp | 16.8-build16843 (including) | 16.8-build16843 (including) |
Manageengine_applications_manager | Zohocorp | 17.0 (including) | 17.0 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170000 (including) | 17.0-build170000 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170001 (including) | 17.0-build170001 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170100 (including) | 17.0-build170100 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170200 (including) | 17.0-build170200 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170300 (including) | 17.0-build170300 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170400 (including) | 17.0-build170400 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170500 (including) | 17.0-build170500 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170600 (including) | 17.0-build170600 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170700 (including) | 17.0-build170700 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170800 (including) | 17.0-build170800 (including) |
Manageengine_applications_manager | Zohocorp | 17.0-build170900 (including) | 17.0-build170900 (including) |