// For flags

CVE-2014-3996

ManageEngine Password Manager - MetadataServlet.dat SQL Injection

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

6
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

Vulnerabilidad de inyección SQL en el servlet LinkViewFetchServlet en la edición ManageEngine Desktop Central (DC) y Desktop Central Managed Service Providers (MSP) anterior a 9 build 90043, la edición Password Manager Pro (PMP) y Password Manager Pro Managed Service Providers (MSP) anterior a 7 build 7003, la edición IT360 y IT360 Managed Service Providers (MSP) anterior a 10.3.3 build 10330, y posiblemente otros productos ManageEngine, permite a atacantes remotos o usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través del parámetro sv en LinkViewFetchServlet.dat.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-06-06 CVE Reserved
  • 2014-08-20 CVE Published
  • 2014-08-25 First Exploit
  • 2024-08-06 CVE Updated
  • 2024-10-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Manageengine
Search vendor "Manageengine"
It360
Search vendor "Manageengine" for product "It360"
<= 10.3.3
Search vendor "Manageengine" for product "It360" and version " <= 10.3.3"
build_10330
Affected
Manageengine
Search vendor "Manageengine"
It360
Search vendor "Manageengine" for product "It360"
<= 10.3.3
Search vendor "Manageengine" for product "It360" and version " <= 10.3.3"
build_10330, managed_service_providers
Affected
Manageengine
Search vendor "Manageengine"
Password Manager Pro
Search vendor "Manageengine" for product "Password Manager Pro"
<= 7.0
Search vendor "Manageengine" for product "Password Manager Pro" and version " <= 7.0"
build_7003
Affected
Manageengine
Search vendor "Manageengine"
Password Manager Pro
Search vendor "Manageengine" for product "Password Manager Pro"
<= 7.0
Search vendor "Manageengine" for product "Password Manager Pro" and version " <= 7.0"
build_7003, managed_service_providers
Affected
Manageengine
Search vendor "Manageengine"
Desktop Central
Search vendor "Manageengine" for product "Desktop Central"
<= 9.0
Search vendor "Manageengine" for product "Desktop Central" and version " <= 9.0"
build_90043
Affected
Manageengine
Search vendor "Manageengine"
Desktop Central
Search vendor "Manageengine" for product "Desktop Central"
<= 9.0
Search vendor "Manageengine" for product "Desktop Central" and version " <= 9.0"
build_90043, managed_service_providers
Affected