CVE-2014-7867
Last modified
CVE-2014-7867 is a vulnerability of currently unknown severity. SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the probeName parameter.. EPSS estimates a 39.93% chance of exploitation in the next 30 days.
Description
SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the probeName parameter.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Opmanager | 11.3 |
| Zohocorp | Manageengine Opmanager | 11.4 |
| Zohocorp | Manageengine Social It Plus | 11.0 |
| Zohocorp | Manageengine It360 | 10.3.0 |
| Zohocorp | Manageengine It360 | 10.4 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-7867?
How severe is CVE-2014-7867?
How do I fix CVE-2014-7867?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-7861The IOHIDSecurePromptClient function in Apple OS X does not …
- CVE-2014-7862The DCPluginServelet servlet in ManageEngine Desktop Central…
- CVE-2014-7863The FailOverHelperServlet (aka FailServlet) servlet in ZOHO …7.5
- CVE-2014-7864Multiple SQL injection vulnerabilities in the FailOverHelper…
- CVE-2014-7865Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2014-7866Multiple directory traversal vulnerabilities in ZOHO ManageE…
- CVE-2014-7868Multiple SQL injection vulnerabilities in ZOHO ManageEngine …
- CVE-2014-7869Cross-site scripting (XSS) vulnerability in the configuratio…
- CVE-2014-7870Cross-site scripting (XSS) vulnerability in the Custom Searc…
- CVE-2014-7871SQL injection vulnerability in Open-Xchange (OX) AppSuite be…
- CVE-2014-7872Comodo GeekBuddy before 4.18.121 does not restrict access to…
- CVE-2014-7874Cross-site request forgery (CSRF) vulnerability in HP System…
Are you affected by CVE-2014-7867?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
