CVE-2020-15533
Description
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated SQL injection in ManageEngine Application Manager's AlarmEscalation module allows attackers to extract or manipulate database contents.
Vulnerability
In Zoho ManageEngine Application Manager version 14.7 (Build 14730, before build 14684 and between builds 14689 and 14750), the AlarmEscalation module is vulnerable to an unauthenticated SQL injection attack [2]. The affected versions include builds that are not between 14684 and 14689 or after 14750 [1][3].
Exploitation
An attacker can exploit this vulnerability without any authentication, requiring network access to the vulnerable Application Manager instance [2]. The attack does not require user interaction or any special privileges, enabling a remote attacker to inject arbitrary SQL commands into the AlarmEscalation module's input parameters [2].
Impact
Successful exploitation allows an attacker to read, modify, or delete database content through the injected SQL commands [2]. This can lead to disclosure of sensitive information, corruption of application data, or potential escalation to more severe attacks depending on the database user's privileges [2]. The exact impact on confidentiality, integrity, or availability is not fully detailed in the available references.
Mitigation
According to ManageEngine, the vulnerability is fixed in Application Manager builds 14684-14688 and build 14750 or later [2]. Users should upgrade to build 14750 or later, or ensure they are on a build between 14684 and 14688 inclusive [3]. No workaround is disclosed in the references if immediate patching is not possible [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine Application Managerdescription
- Range: 14730, between 14684 and 14689, and after 14750
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.manageengine.commitrex_refsource_MISC
- www.manageengine.com/products/applications_manager/issues.htmlmitrex_refsource_CONFIRM
- www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2020-15533.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.