Security advisory for Applications Manager 11.0-14.0

Security advisory for Applications Manager 11.0-14.0

This is a security advisory for all ManageEngine Applications Manager users between versions 11.0 - 14.0. We recommend you to upgrade to the latest version of Applications Manager to avoid the security vulnerability described below.


Vulnerability type: SQL Injection

Severity: High

Issue reported: Privilege exploitation by bypassing the authentication mechanism.

Vulnerability description: In the affected versions unauthorized users could gain access into Applications Manager due to an SQL Injection vulnerability in the following pages:

 

These issues have been assigned CVE-2019-11448 and CVE-2019-11469

Affected versions: Below 14073 

                                Between 14080-14140

Please note that the versions other than the ones mentioned above remain unaffected by the vulnerability.


Solution:

Download service pack and upgrade to the latest version.  Please read the instructions before you upgrade.


References:

 

We offer our sincere apologies for any inconvenience caused.


                New to ADManager Plus?

                  New to ADSelfService Plus?