9.8
CVE-2019-17602
- EPSS 81.55%
- Veröffentlicht 15.10.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:37
- Erkennungen
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Opmanager Version < 12.4
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update -
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124000
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124011
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124012
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124013
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124014
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124015
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124016
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124022
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124023
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124024
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124025
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124026
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124027
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124030
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124033
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124037
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124039
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124040
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124041
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124042
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124043
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124051
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124053
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124054
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124056
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124058
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124065
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124066
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124067
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124069
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124070
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124071
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124074
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124075
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124081
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124082
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124085
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124086
Zohocorp ≫ Manageengine Opmanager Version 12.4 Update build124087
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 81.55% | 0.996 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
https://www.manageengine.com/network-monitoring/help/read-me-complete.html