CVE-2020-16267
Description
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An authenticated SQL injection in Zoho ManageEngine Applications Manager before build 14750 allows attackers to execute arbitrary SQL queries via the RCA module.
Vulnerability
CVE-2020-16267 is an authenticated SQL injection vulnerability in Zoho ManageEngine Applications Manager version 14740 and prior [1][2]. The flaw resides in the RCA (Root Cause Analysis) module, where a crafted JSP request can be used to inject arbitrary SQL commands. Authentication is required to reach the affected code path.
Exploitation
An attacker with valid credentials to the Applications Manager console can send a specially crafted JSP request to the RCA module. The application fails to properly sanitize user-supplied input used in SQL queries, allowing the attacker to execute arbitrary SQL statements. No specific network position beyond authenticated web access is required.
Impact
Successful exploitation allows the attacker to execute arbitrary SQL queries against the backend database. This can lead to disclosure of sensitive data, modification or deletion of database contents, and potentially privilege escalation depending on the database user permissions in the context of the application.
Mitigation
The vulnerability is fixed in build 14750 of the Applications Manager [2][3]; users should upgrade to this build or later. No workaround or patch details for earlier versions are provided; upgrading is the recommended mitigation [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Zoho/ManageEngine Applications Managerdescription
- Range: <=14740
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.manageengine.commitrex_refsource_MISC
- www.manageengine.com/products/applications_manager/issues.htmlmitrex_refsource_CONFIRM
- www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2020-16267.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.