2024-08-01 08:03:12 +00:00
{
"id" : "CVE-2024-5678" ,
"sourceIdentifier" : "0fc0942c-577d-436f-ae8e-945763c79b02" ,
"published" : "2024-08-01T07:15:03.053" ,
2024-08-15 20:03:18 +00:00
"lastModified" : "2024-08-15T18:05:54.847" ,
"vulnStatus" : "Analyzed" ,
2024-08-01 08:03:12 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Zohocorp ManageEngine Applications Manager versions\u00a0170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature."
2024-08-01 14:03:18 +00:00
} ,
{
"lang" : "es" ,
"value" : " Zohocorp ManageEngine Applications Manager versiones 170900 e inferiores son vulnerables a la inyecci\u00f3n SQL autenticada solo para administradores en la funci\u00f3n Create Monitor."
2024-08-01 08:03:12 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-08-15 20:03:18 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "HIGH" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 4.7 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.2 ,
"impactScore" : 3.4
} ,
2024-08-01 08:03:12 +00:00
{
"source" : "0fc0942c-577d-436f-ae8e-945763c79b02" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "HIGH" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 4.7 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.2 ,
"impactScore" : 3.4
}
]
} ,
"weaknesses" : [
2024-08-15 20:03:18 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-89"
}
]
} ,
2024-08-01 08:03:12 +00:00
{
"source" : "0fc0942c-577d-436f-ae8e-945763c79b02" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-89"
}
]
}
] ,
2024-08-15 20:03:18 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "16.8" ,
"matchCriteriaId" : "480B0626-2047-4A6F-8F92-F680D8E2929A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE6C088B-F1DF-4F2A-9E3B-4AD087867A51"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16800:*:*:*:*:*:*" ,
"matchCriteriaId" : "977D742E-A4A3-4197-99CC-86A0630DFC2B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16810:*:*:*:*:*:*" ,
"matchCriteriaId" : "F007885B-D1CF-49E5-BA5E-95C764B7DEA6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16820:*:*:*:*:*:*" ,
"matchCriteriaId" : "EF18E6CE-1D00-4AC6-A0E7-E825B20C27B3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16830:*:*:*:*:*:*" ,
"matchCriteriaId" : "F37D024B-09D7-4199-915B-BF0F91306FF2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16840:*:*:*:*:*:*" ,
"matchCriteriaId" : "1099AC26-DF08-459E-B6DF-31648D40A9EA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16841:*:*:*:*:*:*" ,
"matchCriteriaId" : "2B119FB2-3AB7-4179-A3D9-237843C7B6EC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16842:*:*:*:*:*:*" ,
"matchCriteriaId" : "E084E42D-39B6-4F25-87A6-DDC504F1F464"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:16.8:build16843:*:*:*:*:*:*" ,
"matchCriteriaId" : "618F55F5-58E7-4028-B43B-1C9BE8A545F8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:-:*:*:*:*:*:*" ,
"matchCriteriaId" : "6DBF4AD2-F1FA-4397-872D-15F7F0B499ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170000:*:*:*:*:*:*" ,
"matchCriteriaId" : "24D9A360-987B-4631-AC4E-A83C19AC6218"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170001:*:*:*:*:*:*" ,
"matchCriteriaId" : "CF0F0C0E-7534-490B-B009-8B24E258D8A7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170100:*:*:*:*:*:*" ,
"matchCriteriaId" : "062BCDE1-D732-4482-B537-99857394F8F2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170200:*:*:*:*:*:*" ,
"matchCriteriaId" : "6A6041F0-C3E7-46E6-B38B-8B4487149F58"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170300:*:*:*:*:*:*" ,
"matchCriteriaId" : "AF8451A5-0CCA-48C7-85A4-DD79A5CA1B5F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170400:*:*:*:*:*:*" ,
"matchCriteriaId" : "EAA9B92E-84D6-4AE9-80AB-CFF73D05E4E2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170500:*:*:*:*:*:*" ,
"matchCriteriaId" : "A853E473-DB79-4605-BEA8-82EAE1481253"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170600:*:*:*:*:*:*" ,
"matchCriteriaId" : "5A466A9F-DE75-45F0-9EC5-BAE651E5E491"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170700:*:*:*:*:*:*" ,
"matchCriteriaId" : "F9085451-8E09-43C4-9A59-2F46DE8FDCB8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170800:*:*:*:*:*:*" ,
"matchCriteriaId" : "0D1BA6B5-E27A-451F-8ABB-7C5C2066FBC1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:zohocorp:manageengine_applications_manager:17.0:build170900:*:*:*:*:*:*" ,
"matchCriteriaId" : "FDEDFF09-0539-4833-9568-8AA868506219"
}
]
}
]
}
] ,
2024-08-01 08:03:12 +00:00
"references" : [
{
"url" : "https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2024-5678.html" ,
2024-08-15 20:03:18 +00:00
"source" : "0fc0942c-577d-436f-ae8e-945763c79b02" ,
"tags" : [
"Vendor Advisory"
]
2024-08-01 08:03:12 +00:00
}
]
}