Lucene search

K
cve[email protected]CVE-2014-7868
HistoryDec 04, 2014 - 5:59 p.m.

CVE-2014-7868

2014-12-0417:59:06
CWE-89
web.nvd.nist.gov
26
cve-2014-7868
sql injection
zoho
manageengine
opmanager
it360
social it plus
remote attackers
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

Low

0.964 High

EPSS

Percentile

99.6%

Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in a Delete operation to the APMBVHandler servlet or (2) query parameter in a compare operation to the DataComparisonServlet servlet.

Affected configurations

NVD
Node
zohocorpmanageengine_social_it_plusMatch11.0
Node
zohocorpmanageengine_opmanagerMatch11.3
OR
zohocorpmanageengine_opmanagerMatch11.4
Node
zohocorpmanageengine_it360Match10.3.0
OR
zohocorpmanageengine_it360Match10.4

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.1 High

AI Score

Confidence

Low

0.964 High

EPSS

Percentile

99.6%