SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9488

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities.

CRITICAL 9.8EPSS 4.71%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.

CVSS 3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.71% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-89
Affected
manageengine/applications manager
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.