VYPR
Unrated severityNVD Advisory· Published Oct 6, 2020· Updated Aug 4, 2024

CVE-2020-16267

CVE-2020-16267

Description

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated SQL injection in Zoho ManageEngine Applications Manager before build 14750 allows attackers to execute arbitrary SQL queries via the RCA module.

Vulnerability

CVE-2020-16267 is an authenticated SQL injection vulnerability in Zoho ManageEngine Applications Manager version 14740 and prior [1][2]. The flaw resides in the RCA (Root Cause Analysis) module, where a crafted JSP request can be used to inject arbitrary SQL commands. Authentication is required to reach the affected code path.

Exploitation

An attacker with valid credentials to the Applications Manager console can send a specially crafted JSP request to the RCA module. The application fails to properly sanitize user-supplied input used in SQL queries, allowing the attacker to execute arbitrary SQL statements. No specific network position beyond authenticated web access is required.

Impact

Successful exploitation allows the attacker to execute arbitrary SQL queries against the backend database. This can lead to disclosure of sensitive data, modification or deletion of database contents, and potentially privilege escalation depending on the database user permissions in the context of the application.

Mitigation

The vulnerability is fixed in build 14750 of the Applications Manager [2][3]; users should upgrade to this build or later. No workaround or patch details for earlier versions are provided; upgrading is the recommended mitigation [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.