VYPR
Unrated severityNVD Advisory· Published Oct 6, 2020· Updated Aug 4, 2024

CVE-2020-15927

CVE-2020-15927

Description

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated SQL injection in Zoho ManageEngine Applications Manager <=14740 allows attackers to execute arbitrary SQL via crafted jsp request in SAP module.

Vulnerability

Zoho ManageEngine Applications Manager version 14740 and prior contains a SQL injection vulnerability in the SAP module. An authenticated attacker can send a crafted jsp request to the affected endpoint, leading to arbitrary SQL execution. The vulnerability resides in improper input sanitization of parameters passed to the SAP module's database queries [2][3].

Exploitation

To exploit this vulnerability, an attacker must have valid authentication credentials for the Applications Manager web interface. The attacker crafts a malicious jsp request targeting the SAP module, injecting SQL commands into one or more parameters. No further user interaction is required; the attack is executed against the vulnerable server directly [2][3].

Impact

Successful exploitation allows the attacker to execute arbitrary SQL queries on the underlying database. This can lead to unauthorized reading, modification, or deletion of sensitive data, including configuration information, user credentials, and application logs. Depending on the database privileges, the attacker may also escalate to administrative access or compromise other connected systems [2][3].

Mitigation

The vulnerability is fixed in ManageEngine Applications Manager version 14750, released on 2020-10-06. Users should upgrade to version 14750 or later immediately. No workarounds are documented; the vendor recommends applying the security update as soon as possible [2][3].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.