VYPR
Unrated severityNVD Advisory· Published Oct 1, 2020· Updated Aug 4, 2024

CVE-2020-15533

CVE-2020-15533

Description

In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated SQL injection in ManageEngine Application Manager's AlarmEscalation module allows attackers to extract or manipulate database contents.

Vulnerability

In Zoho ManageEngine Application Manager version 14.7 (Build 14730, before build 14684 and between builds 14689 and 14750), the AlarmEscalation module is vulnerable to an unauthenticated SQL injection attack [2]. The affected versions include builds that are not between 14684 and 14689 or after 14750 [1][3].

Exploitation

An attacker can exploit this vulnerability without any authentication, requiring network access to the vulnerable Application Manager instance [2]. The attack does not require user interaction or any special privileges, enabling a remote attacker to inject arbitrary SQL commands into the AlarmEscalation module's input parameters [2].

Impact

Successful exploitation allows an attacker to read, modify, or delete database content through the injected SQL commands [2]. This can lead to disclosure of sensitive information, corruption of application data, or potential escalation to more severe attacks depending on the database user's privileges [2]. The exact impact on confidentiality, integrity, or availability is not fully detailed in the available references.

Mitigation

According to ManageEngine, the vulnerability is fixed in Application Manager builds 14684-14688 and build 14750 or later [2]. Users should upgrade to build 14750 or later, or ensure they are on a build between 14684 and 14688 inclusive [3]. No workaround is disclosed in the references if immediate patching is not possible [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.