Multiple vulnerabilities in ManageEngine EventLog Analyzer
Using this Log Analyzer software, organizations can automate the entire process of managing terabytes of machine generated logs by collecting, analyzing, correlating, searching, reporting, and archiving from one central location. This event log analyzer software helps to monitor file integrity, conduct log forensics analysis, monitor privileged users and comply to different compliance regulatory bodies by intelligently analyzing your logs and instantly generating a variety of reports like user activity reports, historical trend reports, and more. The first vulnerability is an SQL database information disclosure (read any table in the database) which affects all versions from v7 to v9.9 build 9002. The second vulnerability is Windows / AS/400 managed hosts Administrator credentials disclosure which affects all versions from v7 to v9.9 build 9002.