CVE-2014-3997

UnknownEPSS 9.20%

Last modified

CVE-2014-3997 is a vulnerability of currently unknown severity. SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.. EPSS estimates a 9.20% chance of exploitation in the next 30 days.

Description

SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.

Metrics

EPSS Probability
9.20%

94.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ZohocorpManageengine Password Manager Pro5.0
ZohocorpManageengine Password Manager Pro5.1
ZohocorpManageengine Password Manager Pro5.2
ZohocorpManageengine Password Manager Pro5.3
ZohocorpManageengine Password Manager Pro5.4
ZohocorpManageengine Password Manager Pro6.0
ZohocorpManageengine Password Manager Pro6.1Build6104
ZohocorpManageengine Password Manager Pro6.2
ZohocorpManageengine Password Manager Pro6.3
ZohocorpManageengine Password Manager Pro6.4
ZohocorpManageengine Password Manager Pro6.5
ZohocorpManageengine Password Manager Pro6.6Build6600
ZohocorpManageengine Password Manager Pro6.7Build6700
ZohocorpManageengine Password Manager Pro6.8Build6800
ZohocorpManageengine Password Manager Pro6.9
ZohocorpManageengine Password Manager Pro7.0
ZohocorpManageengine It360<= 10.3.3

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-3997?
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
How severe is CVE-2014-3997?
Severity scoring for CVE-2014-3997 is pending analysis. The EPSS model estimates a 9.20% probability of exploitation in the next 30 days.
How do I fix CVE-2014-3997?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-3997?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST