CVE-2019-19774
By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 12.52% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- zohocorp/manageengine eventlog analyzer
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/156485/ManageEngine-EventLog-Analyzer-10.0-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://gist.github.com/scottgoodwin90/19ccecdc9f5733c0a9381765cfc7fe39Third Party Advisory
- https://www.manageengine.com/products/eventlog/features-new.html#releaseVendor Advisory
- http://packetstormsecurity.com/files/156485/ManageEngine-EventLog-Analyzer-10.0-Information-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://gist.github.com/scottgoodwin90/19ccecdc9f5733c0a9381765cfc7fe39Third Party Advisory
- https://www.manageengine.com/products/eventlog/features-new.html#releaseVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.