ManageEngine.Applications.Manager.removemonitor.SQL.Injection

description-logoDescription

This indicates an attack attempt to exploit a SQL injection vulnerability in ManageEngine Applications Manager.
The vulnerability is caused by lack of sanitizing of user supplied data when the vulnerable software handles a malicious packet. A remote attacker may be able to exploit this to execute arbitrary SQL code on the affected machine via crafted requests.

affected-products-logoAffected Products

ManageEngine Applications Manager prior to 11 build 11912

Impact logoImpact

System Compromise: Remote attackers can execute arbitrary SQL commands on the affected machine

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
https://www.manageengine.com/products/applications_manager/service-packs.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-08-03 25.614 Name:ManageEngine.
ApplicationsManager.
removeMonitorFrmMGSQLInjection:ManageEngine.
Applications.
Manager.
removemonitor.
SQL.
Injection

References

ZDI-15-176