CVE-2024-5678

Zohocorp ManageEngine Applications Manager versions170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
ManageEngineCNA
4.7 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
zohocorpmanageengine_applications_manager
𝑥
< 16.8
zohocorpmanageengine_applications_manager
16.8
zohocorpmanageengine_applications_manager
16.8:build16800
zohocorpmanageengine_applications_manager
16.8:build16810
zohocorpmanageengine_applications_manager
16.8:build16820
zohocorpmanageengine_applications_manager
16.8:build16830
zohocorpmanageengine_applications_manager
16.8:build16840
zohocorpmanageengine_applications_manager
16.8:build16841
zohocorpmanageengine_applications_manager
16.8:build16842
zohocorpmanageengine_applications_manager
16.8:build16843
zohocorpmanageengine_applications_manager
17.0
zohocorpmanageengine_applications_manager
17.0:build170000
zohocorpmanageengine_applications_manager
17.0:build170001
zohocorpmanageengine_applications_manager
17.0:build170100
zohocorpmanageengine_applications_manager
17.0:build170200
zohocorpmanageengine_applications_manager
17.0:build170300
zohocorpmanageengine_applications_manager
17.0:build170400
zohocorpmanageengine_applications_manager
17.0:build170500
zohocorpmanageengine_applications_manager
17.0:build170600
zohocorpmanageengine_applications_manager
17.0:build170700
zohocorpmanageengine_applications_manager
17.0:build170800
zohocorpmanageengine_applications_manager
17.0:build170900
𝑥
= Vulnerable software versions