ManageEngine.Multiple.Products.CustomerName.SQL.Injection

description-logoDescription

This indicates an attack attempt to exploit an SQL injection vulnerability in ManageEngine Applications Manager and ManageEngine IT360 MSP
Edition.
The vulnerability is caused by lack of sanitizing of user supplied data when the vulnerable software handles a malicious packet. A remote attacker may be able to exploit this to execute arbitrary SQL code on the affected machine via crafted requests.

affected-products-logoAffected Products

ManageEngine Applications Manager prior to 11 build 11912
ManageEngine IT360 MSP Edition prior to 11 build 11912

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary SQL commands on affected machines

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
https://www.manageengine.com/products/applications_manager/service-packs.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-08-03 25.614 Name:ManageEngine.
Multi.
Products.
CustomerName.
SQL.
Injection:ManageEngine.
Multiple.
Products.
CustomerName.
SQL.
Injection

References

ZDI-15-232