9.8

CVE-2019-11678

The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Firewall Analyzer Version7.2 Update7020
ZohocorpManageengine Firewall Analyzer Version7.2 Update7021
ZohocorpManageengine Firewall Analyzer Version7.4 Update7400
ZohocorpManageengine Firewall Analyzer Version7.6 Update7600
ZohocorpManageengine Firewall Analyzer Version8.0 Update8000
ZohocorpManageengine Firewall Analyzer Version8.1 Update8110
ZohocorpManageengine Firewall Analyzer Version8.3 Update8300
ZohocorpManageengine Firewall Analyzer Version8.5 Update8500
ZohocorpManageengine Firewall Analyzer Version12.0 Update12000
ZohocorpManageengine Firewall Analyzer Version12.2 Update12200
ZohocorpManageengine Firewall Analyzer Version12.3 Update12300
ZohocorpManageengine Firewall Analyzer Version12.3 Update123008
ZohocorpManageengine Firewall Analyzer Version12.3 Update123027
ZohocorpManageengine Firewall Analyzer Version12.3 Update123045
ZohocorpManageengine Firewall Analyzer Version12.3 Update123057
ZohocorpManageengine Firewall Analyzer Version12.3 Update123064
ZohocorpManageengine Firewall Analyzer Version12.3 Update123070
ZohocorpManageengine Firewall Analyzer Version12.3 Update123083
ZohocorpManageengine Firewall Analyzer Version12.3 Update123092
ZohocorpManageengine Firewall Analyzer Version12.3 Update123126
ZohocorpManageengine Firewall Analyzer Version12.3 Update123129
ZohocorpManageengine Firewall Analyzer Version12.3 Update123137
ZohocorpManageengine Firewall Analyzer Version12.3 Update123151
ZohocorpManageengine Firewall Analyzer Version12.3 Update123156
ZohocorpManageengine Firewall Analyzer Version12.3 Update123164
ZohocorpManageengine Firewall Analyzer Version12.3 Update123169
ZohocorpManageengine Firewall Analyzer Version12.3 Update123177
ZohocorpManageengine Firewall Analyzer Version12.3 Update123182
ZohocorpManageengine Firewall Analyzer Version12.3 Update123185
ZohocorpManageengine Firewall Analyzer Version12.3 Update123186
ZohocorpManageengine Firewall Analyzer Version12.3 Update123194
ZohocorpManageengine Firewall Analyzer Version12.3 Update123197
ZohocorpManageengine Firewall Analyzer Version12.3 Update123208
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 20.87% 0.954
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.