CVE-2014-6043
ManageEngine EventLog Analyzer - Multiple Vulnerabilities
Severity Score
6.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
7
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 y 8.2 build 8020 no restringe correctamente el acceso al navegador de la base de datos, lo que permite a los usuarios autenticados remotos obtener acceso a la base de datos a través de una solicitud directa a event / runQuery.do. Corregido en Build 10000.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-09-01 CVE Reserved
- 2014-09-01 First Exploit
- 2014-09-11 CVE Published
- 2024-08-06 CVE Updated
- 2024-09-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (7)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/34519 | 2014-09-01 | |
http://packetstormsecurity.com/files/128102/ManageEngine-EventLog-Analyzer-9.9-Authorization-Code-Execution.html | 2024-08-06 | |
http://seclists.org/fulldisclosure/2014/Aug/86 | 2024-08-06 | |
http://seclists.org/fulldisclosure/2014/Sep/19 | 2024-08-06 | |
http://www.exploit-db.com/exploits/34519 | 2024-08-06 | |
http://www.securityfocus.com/bid/69482 | 2024-08-06 | |
https://www.mogwaisecurity.de/advisories/MSA-2014-01.txt | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zohocorp Search vendor "Zohocorp" | Manageengine Eventlog Analyzer Search vendor "Zohocorp" for product "Manageengine Eventlog Analyzer" | 8.2 Search vendor "Zohocorp" for product "Manageengine Eventlog Analyzer" and version "8.2" | 8020 |
Affected
| ||||||
Zohocorp Search vendor "Zohocorp" | Manageengine Eventlog Analyzer Search vendor "Zohocorp" for product "Manageengine Eventlog Analyzer" | 9.0 Search vendor "Zohocorp" for product "Manageengine Eventlog Analyzer" and version "9.0" | 9002 |
Affected
|