CVE-2014-7864

Zohocorp Manageengine Opmanager - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1) customerName or (2) serverRole parameter in a standbyUpdateInCentral operation to servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

Exploits (1)

exploitdb WRITEUP
by Pedro Ribeiro · textwebappsmultiple
https://www.exploit-db.com/exploits/43894

Scores

EPSS 0.3219
EPSS Percentile 96.9%

Details

CWE
CWE-89
Status published
Products (14)
zohocorp/manageengine_opmanager 8.8
zohocorp/manageengine_opmanager 9.0
zohocorp/manageengine_opmanager 9.1
zohocorp/manageengine_opmanager 9.2
zohocorp/manageengine_opmanager 9.4
zohocorp/manageengine_opmanager 10.0
zohocorp/manageengine_opmanager 10.1
zohocorp/manageengine_opmanager 10.2
zohocorp/manageengine_opmanager 11.0
zohocorp/manageengine_opmanager 11.1
... and 4 more
Published Feb 04, 2015
Tracked Since Feb 18, 2026