In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_applications_manager | 14.6-build14690 | 14.6-build14690.x |
| zohocorp / manageengine_applications_manager | 14.6-build14683 | 14.6-build14683.x |
| zohocorp / manageengine_applications_manager | 14.6-build14680 | 14.6-build14680.x |
| zohocorp / manageengine_applications_manager | 14.6-build14682 | 14.6-build14682.x |
| zohocorp / manageengine_applications_manager | 14.6-build14681 | 14.6-build14681.x |
| zohocorp / manageengine_applications_manager | 14.6 | 14.6.x |
| zohocorp / manageengine_applications_manager | - | 14.6 |
| zohocorp / manageengine_applications_manager | 14.7-build14700 | 14.7-build14700.x |
| zohocorp / manageengine_applications_manager | 14.7-build14710 | 14.7-build14710.x |
| zohocorp / manageengine_applications_manager | 14.7-build14720 | 14.7-build14720.x |
| zohocorp / manageengine_applications_manager | 14.7-build14730 | 14.7-build14730.x |
| zohocorp / manageengine_applications_manager | 14.7-build14740 | 14.7-build14740.x |
| zohocorp / manageengine_applications_manager | 14.7 | 14.7.x |