Lucene search

K
nvd[email protected]NVD:CVE-2014-3996
HistoryDec 05, 2014 - 3:59 p.m.

CVE-2014-3996

2014-12-0515:59:00
CWE-89
web.nvd.nist.gov
2

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

Low

EPSS

0.935

Percentile

99.2%

SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

Affected configurations

Nvd
Node
manageengineit360Range10.3.3build_10330
OR
manageengineit360Range10.3.3build_10330managed_service_providers
Node
manageenginepassword_manager_proRange7.0build_7003
OR
manageenginepassword_manager_proRange7.0build_7003managed_service_providers
Node
manageenginedesktop_centralRange9.0build_90043
OR
manageenginedesktop_centralRange9.0build_90043managed_service_providers
VendorProductVersionCPE
manageengineit360*cpe:2.3:a:manageengine:it360:*:build_10330:*:*:*:*:*:*
manageengineit360*cpe:2.3:a:manageengine:it360:*:build_10330:*:*:managed_service_providers:*:*:*
manageenginepassword_manager_pro*cpe:2.3:a:manageengine:password_manager_pro:*:build_7003:*:*:*:*:*:*
manageenginepassword_manager_pro*cpe:2.3:a:manageengine:password_manager_pro:*:build_7003:*:*:managed_service_providers:*:*:*
manageenginedesktop_central*cpe:2.3:a:manageengine:desktop_central:*:build_90043:*:*:*:*:*:*
manageenginedesktop_central*cpe:2.3:a:manageengine:desktop_central:*:build_90043:*:*:managed_service_providers:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

Low

EPSS

0.935

Percentile

99.2%