vendor:
Applications Manager
by:
None
9,3
CVSS
CRITICAL
Information Disclosure and Un-Authenticated SQL injection
89, 564
CWE
Product Name: Applications Manager
Affected Version From: ManageEngine Applications Manager Build No: 12700
Affected Version To: ManageEngine Applications Manager Build No: 12700
Patch Exists: YES
Related CWE: None
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
SPSA-2016-02/ManageEngine ApplicationsManager
Some scripts were accessible without authentication, which allowed public access to sensitive data such as licensing information and Monitored Server Details like name IP and maintenance schedule. The downTimeScheduler.do script is vulnerable to a Boolean based blind, and Union based SQL injection, that allows complete unauthorized access to the back-end database, according to the level of privileges of the application database user.
Mitigation:
Upgrade to the latest version of ManageEngine Applications Manager Build No: 12700