Vulnerability record · CVE-2014-3997 · published 5 December 2014
CVE-2014-3997: Zohocorp manageengine password manager pro sql injection vulnerability
Zohocorp · Manageengine Password Manager Pro
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
Description
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2014/Aug/55 | ExploitMailing ListThird Party Advisory |
| http://seclists.org/fulldisclosure/2014/Aug/85 | ExploitMailing ListThird Party Advisory |
| https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_dc_pmp_it360_sqli.txt | Exploit |
| https://raw.githubusercontent.com/pedrib/PoC/master/msf_modules/manageengine_dc_pmp_sqli.rb | Exploit |
| http://seclists.org/fulldisclosure/2014/Aug/55 | ExploitMailing ListThird Party Advisory |
| http://seclists.org/fulldisclosure/2014/Aug/85 | ExploitMailing ListThird Party Advisory |
| https://raw.githubusercontent.com/pedrib/PoC/master/ManageEngine/me_dc_pmp_it360_sqli.txt | Exploit |
| https://raw.githubusercontent.com/pedrib/PoC/master/msf_modules/manageengine_dc_pmp_sqli.rb | Exploit |
Track CVE-2014-3997 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3997), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.