← Vulnerability feed

Vulnerability record · CVE-2014-6039 · published 13 January 2020

CVE-2014-6039: ManageEngine EventLog Analyzer credential disclosure

Zohocorp · Manageengine Eventlog Analyzer

ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose credentials through insufficiently protected storage (CWE-522). The flaw is remotely reachable without authentication and leaks sensitive credential data, which matters because those credentials can unlock further systems. The record does not specify the exact disclosure mechanism beyond the SQL credential disclosure reference title.

7.5 CVSS 3.1 High EPSS 69% · top 0.7% CWE-522 · Insufficiently protected credentials
7.5CVSS 3.1 base score, v2 5.0
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote credential disclosure with public exploit references and very high EPSS, though not in KEV and requiring an unpatched legacy version.

What it is

ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose credentials through insufficiently protected storage (CWE-522). The flaw is remotely reachable without authentication and leaks sensitive credential data, which matters because those credentials can unlock further systems. The record does not specify the exact disclosure mechanism beyond the SQL credential disclosure reference title.

Impact

An unauthenticated attacker gains access to credentials, likely database or application credentials, enabling lateral movement or direct access to connected systems.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not state which endpoint or interface exposes the credentials.

Exploitation

Not listed in CISA KEV, but EPSS is 0.68779 (99.3rd percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade to ManageEngine EventLog Analyzer 10 Build 10000 or later, the stated fixed version.
  • If upgrade is not immediate, restrict network access to the EventLog Analyzer interface to trusted management networks only.
  • Rotate any credentials that may have been exposed by the affected instance, including database and service accounts.
  • Audit logs for access to the vulnerable interface from untrusted sources.

Detection

  • Monitor network logs for unauthenticated requests to EventLog Analyzer endpoints from unexpected hosts.
  • Search application and web server logs for patterns matching the public exploit references.
  • Alert on outbound authentication attempts using EventLog Analyzer service or database credentials from unusual sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-6039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28959Zohocorp manageengine eventlog analyzer path traversal vulnerabilityZoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to r…EPSS 17%9.8CVE-2020-24786Zohocorp manageengine adselfservice plus improper authentication vulnerabilityAn issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…EPSS 13%8.8CVE-2019-19774Zohocorp manageengine eventlog analyzer vulnerabilityAn issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /…EPSS 13%8.1CVE-2023-35785Zohocorp manageengine ad360 improper authentication vulnerabilityZoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…EPSS 2.4%7.8CVE-2019-12133Zohocorp manageengine analytics plus uncontrolled search path element vulnerabilityMultiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…EPSS 1.7%7.5CVE-2014-6038ManageEngine EventLog Analyzer database information disclosureZoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose database information to unauthenticated remote users. The flaw is an inf…EPSS 73%analysed7.5CVE-2015-7387ManageEngine EventLog Analyzer SQL injection via runQuery.do query parameterZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier fails to properly restrict the query parameter to event/runQuery.do, allowing an all…EPSS 80%analysed7.5CVE-2014-6037ManageEngine EventLog Analyzer agentUpload path traversal leads to remote code executionThe agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 is vulnerable to directory traversal. An attacker ca…EPSS 84%analysed

Source: NIST National Vulnerability Database (record CVE-2014-6039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.