CVE-2020-15533

In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
zohocorpmanageengine_applications_manager
𝑥
< 14.6
zohocorpmanageengine_applications_manager
14.6
zohocorpmanageengine_applications_manager
14.6:build14680
zohocorpmanageengine_applications_manager
14.6:build14681
zohocorpmanageengine_applications_manager
14.6:build14682
zohocorpmanageengine_applications_manager
14.6:build14683
zohocorpmanageengine_applications_manager
14.6:build14690
zohocorpmanageengine_applications_manager
14.7
zohocorpmanageengine_applications_manager
14.7:build14700
zohocorpmanageengine_applications_manager
14.7:build14710
zohocorpmanageengine_applications_manager
14.7:build14720
zohocorpmanageengine_applications_manager
14.7:build14730
zohocorpmanageengine_applications_manager
14.7:build14740
𝑥
= Vulnerable software versions