Vulnerability Description
SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Password Manager Pro | <= 7.1 |
Related Weaknesses (CWE)
References
- http://osvdb.org/show/osvdb/114483Broken Link
- http://packetstormsecurity.com/files/129036/Password-Manager-Pro-SQL-Injection.hExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2014/Nov/18ExploitMailing ListThird Party Advisory
- http://www.exploit-db.com/exploits/35210ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/71016Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98596VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_pmp_privesc.Exploit
- http://osvdb.org/show/osvdb/114483Broken Link
- http://packetstormsecurity.com/files/129036/Password-Manager-Pro-SQL-Injection.hExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2014/Nov/18ExploitMailing ListThird Party Advisory
- http://www.exploit-db.com/exploits/35210ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/71016Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98596VDB Entry
- https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_pmp_privesc.Exploit
FAQ
What is CVE-2014-8498?
CVE-2014-8498 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote a...
How severe is CVE-2014-8498?
CVE-2014-8498 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8498?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Password Manager Pro.