MEDIUM · 6.5

CVE-2014-6043

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the databas...

Vulnerability Description

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.

CVSS Score

6.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
ZohocorpManageengine Eventlog Analyzer8.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-6043?

CVE-2014-6043 is a vulnerability with a CVSS score of 6.5 (MEDIUM). ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the databas...

How severe is CVE-2014-6043?

CVE-2014-6043 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-6043?

Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Eventlog Analyzer.