Vulnerability Details | |
---|---|
Impact | CVSS V3 rating: 8.8 CRITICAL |
Fixed | 19 October 2020 |
Affected Builds | Below 14880 |
Fixed in | Version 14880 and above |
Overview | Post Authenticated SQL Injection attack in AlarmView module. |
Recommended Fix | Upgrade Applications Manager to version 14880 or above. |
Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted AlarmView request.
We recommend you to upgrade Applications Manager to version 14880 or above to fix this issue.
Source and Acknowledgements
Find out more about CVE-2020-27733 from CVE Directory and NIST NVD.
Reported by:
Whoami from VSEC Redteam
For clarification or corrections please contact our support team or email us at appmanager-support@manageengine.com
It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.
Reviewer Role: Research and Development