CVE-2014-7864

Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1) customerName or (2) serverRole parameter in a standbyUpdateInCentral operation to servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
zohocorpmanageengine_opmanager
8.8
zohocorpmanageengine_opmanager
9.0
zohocorpmanageengine_opmanager
9.1
zohocorpmanageengine_opmanager
9.2
zohocorpmanageengine_opmanager
9.4
zohocorpmanageengine_opmanager
10.0
zohocorpmanageengine_opmanager
10.1
zohocorpmanageengine_opmanager
10.2
zohocorpmanageengine_opmanager
11.0
zohocorpmanageengine_opmanager
11.1
zohocorpmanageengine_opmanager
11.2
zohocorpmanageengine_opmanager
11.3
zohocorpmanageengine_opmanager
11.4
zohocorpmanageengine_opmanager
11.5
𝑥
= Vulnerable software versions