CVE-2020-15533

CRITICAL

Zoho ManageEngine Application Manager < 14.6 - Unauthenticated SQL Injection in AlarmEscalation Module

Title source: llm
STIX 2.1

Description

In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.1145
EPSS Percentile 93.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (3)
zohocorp/manageengine_applications_manager 14.6 (6 CPE variants)
zohocorp/manageengine_applications_manager 14.7 (6 CPE variants)
zohocorp/manageengine_applications_manager < 14.6
Published Oct 01, 2020
Tracked Since Feb 18, 2026