Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.0:*:*:*:-:*:*:*", "matchCriteriaId": "A5E5F536-9AB1-4D3F-A8DC-6242AF30DB19", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.1:*:*:*:-:*:*:*", "matchCriteriaId": "4CEE22EB-EB76-4B56-A118-C204EA0F106D", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.2:*:*:*:-:*:*:*", "matchCriteriaId": "75EDFEEE-694C-488B-A6F8-95B0D1360E69", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.3:*:*:*:-:*:*:*", "matchCriteriaId": "E197858B-2FB6-471C-88B9-2C69BA6A2090", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.4:*:*:*:-:*:*:*", "matchCriteriaId": "5A0CC732-5D68-4890-BC3B-B02DA372FD54", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.0:*:*:*:-:*:*:*", "matchCriteriaId": "FA458408-3EFA-439D-9EFD-84A4C5B477B1", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.0:build6002:*:*:-:*:*:*", "matchCriteriaId": "BCC8AAA2-B079-43C7-BC3E-920954AF5685", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.1:build6104:*:*:-:*:*:*", "matchCriteriaId": "1F91875D-75A0-4823-84DC-C082567CA84E", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.2:*:*:*:-:*:*:*", "matchCriteriaId": "2DFF99B9-C5D0-44A1-B54B-301CA1704CA6", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.2:build6201:*:*:-:*:*:*", "matchCriteriaId": "27071ED3-C20D-4B9D-9442-44EC9D6E8DD3", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.3:*:*:*:-:*:*:*", "matchCriteriaId": "655D238F-5345-42FB-8031-8EB48664AC30", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:*:*:*:-:*:*:*", "matchCriteriaId": "3DD9310B-3D5B-4A16-A0D6-F604F76E1100", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6401:*:*:-:*:*:*", "matchCriteriaId": "B5F16F44-2426-43B9-BE33-4E7FEA7036FC", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6402:*:*:-:*:*:*", "matchCriteriaId": "90E96158-B75D-40C2-A5E7-493974A2AEED", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6403:*:*:-:*:*:*", "matchCriteriaId": "50DD364E-2817-487F-A2F3-F29AF3EFB8D7", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6404:*:*:-:*:*:*", "matchCriteriaId": "70077945-E672-4831-A81B-AB4778256D3C", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:*:*:*:-:*:*:*", "matchCriteriaId": "73887589-69A9-4FEF-8BC5-89BD7EDBF924", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:build6503:*:*:-:*:*:*", "matchCriteriaId": "B9DFFF51-430B-4FCA-9B14-DD0DC4322E35", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:build6504:*:*:-:*:*:*", "matchCriteriaId": "6553FBD9-7E29-4663-9DCC-1F5AC8C215AF", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:build6505:*:*:-:*:*:*", "matchCriteriaId": "B865BD30-39E6-4674-8DF4-5971A63B24AB", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.6:build6600:*:*:-:*:*:*", "matchCriteriaId": "55FD92EC-8065-4CBF-8370-B28B3E81C005", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.7:build6700:*:*:-:*:*:*", "matchCriteriaId": "73CA5EFF-EF35-4030-830C-4D492DC440D6", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.7:build6701:*:*:-:*:*:*", "matchCriteriaId": "F4E376B5-D710-44FB-A3BA-CBF96781D1CB", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6800:*:*:-:*:*:*", "matchCriteriaId": "AB784C5F-B0E1-4942-8D96-510419D789CF", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6801:*:*:-:*:*:*", "matchCriteriaId": "E1DA7102-44CE-44EE-8750-05C12061E437", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6802:*:*:-:*:*:*", "matchCriteriaId": "B147154E-3960-44D8-8BE8-7A6DF5192ED2", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6803:*:*:-:*:*:*", "matchCriteriaId": "3135E48F-1CF2-4DC6-A066-BEBED1664205", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:*:*:*:-:*:*:*", "matchCriteriaId": "75B96AEC-BB98-44A1-A118-710DA71CDCC1", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6900:*:*:-:*:*:*", "matchCriteriaId": "47491EFB-44B0-45C2-A50E-55F9BDC6052B", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6901:*:*:-:*:*:*", "matchCriteriaId": "472440BF-EFA4-4959-B671-2F7D653D324D", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6902:*:*:-:*:*:*", "matchCriteriaId": "4369642E-9DD7-4181-8F1C-89C340BFBE2E", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6903:*:*:-:*:*:*", "matchCriteriaId": "B6AB46C0-5570-4C8D-BF45-12475310020E", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6904:*:*:-:*:*:*", "matchCriteriaId": "7A6F8938-C37C-4B7F-9A12-A82640C69CBD", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:*:*:*:-:*:*:*", "matchCriteriaId": "1603D672-C8ED-42A5-84AF-B8B7818BE9E4", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7000:*:*:-:*:*:*", "matchCriteriaId": "F7041071-8EBB-4B4D-99EA-E7CA6B6021E1", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7001:*:*:-:*:*:*", "matchCriteriaId": "15A26E93-897D-4E2B-9A59-A4BAEB0F05B8", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7002:*:*:-:*:*:*", "matchCriteriaId": "3A31DA9A-3F01-40E2-8564-AE515B83D974", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7003:*:*:-:*:*:*", "matchCriteriaId": "DEE65B08-E206-4D2A-B274-C8C03910BF15", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:zohocorp:manageengine_it360:*:*:*:*:-:*:*:*", "matchCriteriaId": "ECF59D56-5CC9-414B-9CE1-DB53E9282ADF", "versionEndIncluding": "10.3.3", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_it360:*:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "FA790610-402F-413B-8BF8-8357193E27A4", "versionEndIncluding": "10.3.3", "vulnerable": true}], "negate": false, "operator": "OR"}]}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.0:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "6A2D0F09-5F20-473F-98C3-DA31B5A7AAF5", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.1:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "2CBE694B-0B6D-4C4C-87AC-7FE0F88F211E", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.2:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "50FB56D1-D150-47F9-B8DB-2EA27A6220B8", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.3:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "BB57288B-2688-4FAB-B1C3-AF3C208B4C87", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:5.4:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "3075719E-D879-42E5-B604-F1F0A14CA197", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.0:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "1FA339F7-ED6B-4514-91F7-0BB38F29CD0F", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.0:build6002:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "D6CC265D-2D91-4A19-87F7-904B920106DD", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.1:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "B01FB0FC-9705-462B-8A5C-69D5D52C8EBF", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.1:build6104:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "133BDD75-D6CB-40CD-B1CF-6D5678E1DEFE", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.2:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "FDECD276-38D9-4EF6-8BF2-DC79BFB9E8BD", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.2:build6201:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "A9CCC8F7-3508-4136-9F94-5B6443D35B5E", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.3:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "A1C40444-0385-4F96-976C-5D59CA88E7CD", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "019FA9DB-4FDD-42FE-8E1E-8E22A32EC518", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6401:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "862C8B61-3B4A-447C-A286-40FCA3E921CF", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6402:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "8D035C4F-F0BA-4A67-ABE1-C2DF3F3C42A1", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6403:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "C79C8547-72A8-49EF-93DC-0CA932B3720C", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.4:build6404:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "45A56669-35DF-4E77-8A56-B5DDD4073A5E", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "E122344B-C813-43DF-A9A0-DE1293A0BC35", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:build6503:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "3BB0010E-6553-4BA2-A9C9-D7F5A6DC14F1", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:build6504:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "F5270D44-D7C0-4CB7-A72C-393225A33005", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.5:build6505:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "23AD6263-D363-44BD-BDF8-5DACBFA7AA49", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.6:build6600:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "6F801D6A-ABB1-4B20-A027-545AF3B7BA83", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.7:build6700:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "94C0DB11-19DD-4A65-8A29-F6401E788B62", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.7:build6701:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "3B7A79E9-FD83-493B-8928-7BF4C7611977", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6800:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "576F4055-FDCD-426C-8A8C-F4F944847873", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6801:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "EFFAA39D-1DEB-4728-A481-62A13F585F70", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6802:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "C2D7736E-5F5B-4155-B8F5-2C37A9DD4059", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.8:build6803:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "F76B409F-5994-4DDD-A5E5-920F5C8EEE43", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "81915238-4492-4726-95F2-D50741A4B400", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6900:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "BD5C993F-4D25-4BF9-8577-19F84FB22F25", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6901:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "183FA742-E32E-4A0C-95DD-53FE7925B489", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6902:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "2A1FD798-614B-43C1-9E22-DF4F63AAB10D", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6903:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "80BECF57-5EC5-41E5-9489-755FABD5AB64", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:6.9:build6904:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "04ED9F67-3A2A-4713-BFEB-357D8C480CA7", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:*:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "AE1102C2-99A2-4992-B8FF-233927BFB942", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7000:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "E73F239A-5C13-431B-9F8E-EA53B5DE990B", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7001:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "C12F95B5-94C2-4FB2-A0C0-B51BAF651410", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7002:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "DC0767D1-877A-47F7-AF43-C2073DB2F70F", "vulnerable": true}, {"criteria": "cpe:2.3:a:zohocorp:manageengine_password_manager_pro:7.0:build7003:*:*:managed_service_providers:*:*:*", "matchCriteriaId": "2F8FDB70-0622-4258-B365-F682A6B0AA2E", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat."}, {"lang": "es", "value": "Vulnerabilidad de inyecci\u00f3n SQL en el servlet MetadataServlet en la edici\u00f3n ManageEngine Password Manager Pro (PMP) y Password Manager Pro Managed Service Providers (MSP) 5 hasta 7 build 7003, la edici\u00f3n IT360 y IT360 Managed Service Providers (MSP) anterior a 10.3.3 build 10330, y posiblemente otros productos ManageEngine, permite a atacantes remotos o usuarios remotos autenticados ejecutar comandos SQL arbitrarios a trav\u00e9s del par\u00e1metro sv en MetadataServlet.dat."}], "id": "CVE-2014-3997", "lastModified": "2025-04-12T10:46:40.837", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 7.5, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "version": "2.0"}, "exploitabilityScore": 10.0, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false}]}, "published": "2014-12-05T15:59:01.353", "references": [{"source": "cve@mitre.org", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2014/Aug/55"}, {"source": "cve@mitre.org", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2014/Aug/85"}, {"source": "cve@mitre.org", "tags": ["Exploit"], "url": "https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_dc_pmp_it360_sqli.txt"}, {"source": "cve@mitre.org", "tags": ["Exploit"], "url": "https://raw.githubusercontent.com/pedrib/PoC/master/msf_modules/manageengine_dc_pmp_sqli.rb"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2014/Aug/55"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Mailing List", "Third Party Advisory"], "url": "http://seclists.org/fulldisclosure/2014/Aug/85"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit"], "url": "https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_dc_pmp_it360_sqli.txt"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit"], "url": "https://raw.githubusercontent.com/pedrib/PoC/master/msf_modules/manageengine_dc_pmp_sqli.rb"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-89"}], "source": "nvd@nist.gov", "type": "Primary"}]}