doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.
| Software | From | Fixed in |
|---|---|---|
| zohocorp / manageengine_applications_manager | 14.9-build14900 | 14.9-build14900.x |
| zohocorp / manageengine_applications_manager | 14.9-build14910 | 14.9-build14910.x |
| zohocorp / manageengine_applications_manager | 14.9-build14911 | 14.9-build14911.x |
| zohocorp / manageengine_applications_manager | 14.9-build14930 | 14.9-build14930.x |
| zohocorp / manageengine_applications_manager | 14.9 | 14.9.x |
| zohocorp / manageengine_applications_manager | - | 14.9 |