← Vulnerability feed

Vulnerability record · CVE-2014-6038 · published 13 January 2020

CVE-2014-6038: ManageEngine EventLog Analyzer database information disclosure

Zohocorp · Manageengine Eventlog Analyzer

Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose database information to unauthenticated remote users. The flaw is an information exposure issue (CWE-200) that leaks SQL credentials, and it is fixed in EventLog Analyzer 10.0 Build 10000. Because the leaked data includes database credentials, it can enable follow-on access to the underlying database.

7.5 CVSS 3.1 High EPSS 73% · top 0.6% CWE-200 · Information exposure
7.5CVSS 3.1 base score, v2 5.0
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable disclosure of database credentials with public exploit code and very high EPSS, though not listed in KEV.

What it is

Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose database information to unauthenticated remote users. The flaw is an information exposure issue (CWE-200) that leaks SQL credentials, and it is fixed in EventLog Analyzer 10.0 Build 10000. Because the leaked data includes database credentials, it can enable follow-on access to the underlying database.

Impact

An attacker gains sensitive database information, including SQL credentials, without authentication. That exposure can be used to reach or compromise the backend database and the log data it stores.

Attack surface

The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the vulnerable endpoint is directly accessible over the network. No authentication or victim action is required.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.72757, 99.42nd percentile) and public references are tagged Exploit, indicating exploit code is publicly available.

What to do

  • Upgrade to EventLog Analyzer 10.0 Build 10000 or later; versions 7 through 9.9 build 9002 are affected.
  • If upgrade is not immediately possible, restrict network access to the EventLog Analyzer web interface to trusted management networks only.
  • Rotate any database credentials that the product uses, since the flaw discloses SQL credentials.
  • Review database and application logs for unauthorized access using credentials associated with EventLog Analyzer.

Detection

  • Monitor network traffic and web logs for requests to EventLog Analyzer endpoints that return database or credential data.
  • Alert on access to the EventLog Analyzer interface from unexpected or external source IP addresses.
  • Audit database authentication logs for logins using EventLog Analyzer service accounts from unusual hosts or times.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-6038 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28959Zohocorp manageengine eventlog analyzer path traversal vulnerabilityZoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to r…EPSS 17%9.8CVE-2020-24786Zohocorp manageengine adselfservice plus improper authentication vulnerabilityAn issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…EPSS 13%8.8CVE-2019-19774Zohocorp manageengine eventlog analyzer vulnerabilityAn issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /…EPSS 13%8.1CVE-2023-35785Zohocorp manageengine ad360 improper authentication vulnerabilityZoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…EPSS 2.4%7.8CVE-2019-12133Zohocorp manageengine analytics plus uncontrolled search path element vulnerabilityMultiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…EPSS 1.7%7.5CVE-2014-6039ManageEngine EventLog Analyzer credential disclosureManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose credentials through insufficiently protected storage (CWE-522). The flaw is r…EPSS 69%analysed7.5CVE-2015-7387ManageEngine EventLog Analyzer SQL injection via runQuery.do query parameterZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier fails to properly restrict the query parameter to event/runQuery.do, allowing an all…EPSS 80%analysed7.5CVE-2014-6037ManageEngine EventLog Analyzer agentUpload path traversal leads to remote code executionThe agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 is vulnerable to directory traversal. An attacker ca…EPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2014-6038), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.