CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
Low
EPSS
Percentile
42.0%
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to fault/AlarmView.do or (2) period parameter to showHistoryData.do.
Vendor | Product | Version | CPE |
---|---|---|---|
manageengine | applications_manager | 10.0 | cpe:2.3:a:manageengine:applications_manager:10.0:*:*:*:*:*:*:* |
manageengine | applications_manager | 10.1 | cpe:2.3:a:manageengine:applications_manager:10.1:*:*:*:*:*:*:* |
manageengine | applications_manager | 10.2 | cpe:2.3:a:manageengine:applications_manager:10.2:*:*:*:*:*:*:* |
manageengine | applications_manager | 10.3 | cpe:2.3:a:manageengine:applications_manager:10.3:*:*:*:*:*:*:* |
manageengine | applications_manager | 9.1 | cpe:2.3:a:manageengine:applications_manager:9.1:*:*:*:*:*:*:* |
manageengine | applications_manager | 9.2 | cpe:2.3:a:manageengine:applications_manager:9.2:*:*:*:*:*:*:* |
manageengine | applications_manager | 9.3 | cpe:2.3:a:manageengine:applications_manager:9.3:*:*:*:*:*:*:* |
manageengine | applications_manager | 9.4 | cpe:2.3:a:manageengine:applications_manager:9.4:*:*:*:*:*:*:* |
manageengine | applications_manager | 9.5 | cpe:2.3:a:manageengine:applications_manager:9.5:*:*:*:*:*:*:* |