Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:SQL:INJ:MANAGEENGINE-APP

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

ManageEngine Applications Manager MenuHandlerServlet SQL Injection

Release Date

2017/04/25

Update Number

2875

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: ManageEngine Applications Manager MenuHandlerServlet SQL Injection


This signature detects attempts to exploit a known vulnerability in ManageEngine Applications Manager. By sending crafted request messages, a remote unauthenticated attacker can exploit this vulnerability to inject and execute arbitrary SQL statements on the affected system with the privileges of SYSTEM.

Extended Description

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.

Affected Products

  • Manageengine applications_manager 12.0
  • Manageengine applications_manager 13.0

References

  • CVE: CVE-2016-9488

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out