CVE-2025-9428

Zohocorp ManageEngine Analytics Plus versions6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
ZohocorpCNA
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
zohocorpmanageengine_analytics_plus
𝑥
< 6.1
zohocorpmanageengine_analytics_plus
6.1:6100
zohocorpmanageengine_analytics_plus
6.1:6110
zohocorpmanageengine_analytics_plus
6.1:6120
zohocorpmanageengine_analytics_plus
6.1:6130
zohocorpmanageengine_analytics_plus
6.1:6140
zohocorpmanageengine_analytics_plus
6.1:6150
zohocorpmanageengine_analytics_plus
6.1:6160
zohocorpmanageengine_analytics_plus
6.1:6170
zohocorpmanageengine_analytics_plus
6.1:6171
𝑥
= Vulnerable software versions