Lucene search

K
cveMitreCVE-2014-6043
HistorySep 11, 2014 - 3:55 p.m.

CVE-2014-6043

2014-09-1115:55:05
CWE-264
mitre
web.nvd.nist.gov
24
cve-2014-6043
zoho
manageengine
eventlog analyzer
security
database access

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.013

Percentile

86.2%

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.

Affected configurations

Nvd
Node
zohocorpmanageengine_eventlog_analyzerMatch8.28020
OR
zohocorpmanageengine_eventlog_analyzerMatch9.09002
VendorProductVersionCPE
zohocorpmanageengine_eventlog_analyzer8.2cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer:8.2:8020:*:*:*:*:*:*
zohocorpmanageengine_eventlog_analyzer9.0cpe:2.3:a:zohocorp:manageengine_eventlog_analyzer:9.0:9002:*:*:*:*:*:*

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.013

Percentile

86.2%

Related for CVE-2014-6043