Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html | exploit vdb entry third party advisory |
http://www.securityfocus.com/bid/70959 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98540 | vdb entry |
http://seclists.org/fulldisclosure/2014/Nov/12 | third party advisory mailing list |