CVE-2024-5678

EUVD-2024-46851
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
ManageEngineCNA
4.7 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_applications_manager
𝑥
< 16.8
zohocorpmanageengine_applications_manager
16.8
zohocorpmanageengine_applications_manager
16.8:build16800
zohocorpmanageengine_applications_manager
16.8:build16810
zohocorpmanageengine_applications_manager
16.8:build16820
zohocorpmanageengine_applications_manager
16.8:build16830
zohocorpmanageengine_applications_manager
16.8:build16840
zohocorpmanageengine_applications_manager
16.8:build16841
zohocorpmanageengine_applications_manager
16.8:build16842
zohocorpmanageengine_applications_manager
16.8:build16843
zohocorpmanageengine_applications_manager
17.0
zohocorpmanageengine_applications_manager
17.0:build170000
zohocorpmanageengine_applications_manager
17.0:build170001
zohocorpmanageengine_applications_manager
17.0:build170100
zohocorpmanageengine_applications_manager
17.0:build170200
zohocorpmanageengine_applications_manager
17.0:build170300
zohocorpmanageengine_applications_manager
17.0:build170400
zohocorpmanageengine_applications_manager
17.0:build170500
zohocorpmanageengine_applications_manager
17.0:build170600
zohocorpmanageengine_applications_manager
17.0:build170700
zohocorpmanageengine_applications_manager
17.0:build170800
zohocorpmanageengine_applications_manager
17.0:build170900
𝑥
= Vulnerable software versions