7.5
CVE-2014-3997
- EPSS 1.29%
- Veröffentlicht 05.12.2014 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Password Manager Pro Version5.0 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version5.1 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version5.2 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version5.3 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version5.4 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.0 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.0 Updatebuild6002 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.1 Updatebuild6104 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.2 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.2 Updatebuild6201 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.3 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6401 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6402 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6403 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6404 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 Updatebuild6503 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 Updatebuild6504 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 Updatebuild6505 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.6 Updatebuild6600 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.7 Updatebuild6700 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.7 Updatebuild6701 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6800 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6801 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6802 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6803 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6900 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6901 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6902 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6903 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6904 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7000 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7001 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7002 SwEdition-
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7003 SwEdition-
Zohocorp ≫ Manageengine It360 SwEdition- Version <= 10.3.3
Zohocorp ≫ Manageengine It360 SwEditionmanaged_service_providers Version <= 10.3.3
Zohocorp ≫ Manageengine Password Manager Pro Version5.0 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version5.1 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version5.2 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version5.3 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version5.4 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.0 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.0 Updatebuild6002 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.1 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.1 Updatebuild6104 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.2 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.2 Updatebuild6201 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.3 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6401 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6402 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6403 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.4 Updatebuild6404 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 Updatebuild6503 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 Updatebuild6504 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.5 Updatebuild6505 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.6 Updatebuild6600 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.7 Updatebuild6700 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.7 Updatebuild6701 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6800 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6801 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6802 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.8 Updatebuild6803 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6900 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6901 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6902 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6903 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version6.9 Updatebuild6904 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7000 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7001 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7002 SwEditionmanaged_service_providers
Zohocorp ≫ Manageengine Password Manager Pro Version7.0 Updatebuild7003 SwEditionmanaged_service_providers
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.29% | 0.779 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.