CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.71% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- manageengine/applications manager
- Source
- cret@cert.org
References
- http://packetstormsecurity.com/files/158554/ManageEngine-Applications-Manager-13-SQL-Injection.html
- http://seclists.org/fulldisclosure/2017/Apr/9Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/97394Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/142022/ManageEngine-Applications-Manager-12-13-XSS-SQL-Injection-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2016-9488.html
- http://packetstormsecurity.com/files/158554/ManageEngine-Applications-Manager-13-SQL-Injection.html
- http://seclists.org/fulldisclosure/2017/Apr/9Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/97394Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/142022/ManageEngine-Applications-Manager-12-13-XSS-SQL-Injection-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2016-9488.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.