Vulnerability record · CVE-2014-6038 · published 13 January 2020
CVE-2014-6038: ManageEngine EventLog Analyzer database information disclosure
Zohocorp · Manageengine Eventlog Analyzer
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose database information to unauthenticated remote users. The flaw is an information exposure issue (CWE-200) that leaks SQL credentials, and it is fixed in EventLog Analyzer 10.0 Build 10000. Because the leaked data includes database credentials, it can enable follow-on access to the underlying database.
Description
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable disclosure of database credentials with public exploit code and very high EPSS, though not listed in KEV.
What it is
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose database information to unauthenticated remote users. The flaw is an information exposure issue (CWE-200) that leaks SQL credentials, and it is fixed in EventLog Analyzer 10.0 Build 10000. Because the leaked data includes database credentials, it can enable follow-on access to the underlying database.
Impact
An attacker gains sensitive database information, including SQL credentials, without authentication. That exposure can be used to reach or compromise the backend database and the log data it stores.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the vulnerable endpoint is directly accessible over the network. No authentication or victim action is required.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.72757, 99.42nd percentile) and public references are tagged Exploit, indicating exploit code is publicly available.
What to do
- Upgrade to EventLog Analyzer 10.0 Build 10000 or later; versions 7 through 9.9 build 9002 are affected.
- If upgrade is not immediately possible, restrict network access to the EventLog Analyzer web interface to trusted management networks only.
- Rotate any database credentials that the product uses, since the flaw discloses SQL credentials.
- Review database and application logs for unauthorized access using credentials associated with EventLog Analyzer.
Detection
- Monitor network traffic and web logs for requests to EventLog Analyzer endpoints that return database or credential data.
- Alert on access to the EventLog Analyzer interface from unexpected or external source IP addresses.
- Audit database authentication logs for logins using EventLog Analyzer service accounts from unusual hosts or times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2014/Nov/12 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/70959 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/98540 | VDB Entry |
| http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2014/Nov/12 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/70959 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/98540 | VDB Entry |
Track CVE-2014-6038 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-6038), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.