Database Query Authentication Flaw in Zoho ManageEngine Product
CVE-2018-5338

9.8CRITICAL

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
18 April 2018

What is CVE-2018-5338?

A vulnerability exists within Zoho's ManageEngine Desktop Central, where a flaw in the authentication and authorization mechanism allows unauthorized access to database queries. This exposes sensitive information and could lead to elevation of privileges for attackers. Users of versions 10.0.124 and 10.0.184 are particularly at risk, underscoring the need for immediate updates and security measures as highlighted in various advisories.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.