Vulnerability record · CVE-2014-6039 · published 13 January 2020
CVE-2014-6039: ManageEngine EventLog Analyzer credential disclosure
Zohocorp · Manageengine Eventlog Analyzer
ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose credentials through insufficiently protected storage (CWE-522). The flaw is remotely reachable without authentication and leaks sensitive credential data, which matters because those credentials can unlock further systems. The record does not specify the exact disclosure mechanism beyond the SQL credential disclosure reference title.
Description
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated remote credential disclosure with public exploit references and very high EPSS, though not in KEV and requiring an unpatched legacy version.
What it is
ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose credentials through insufficiently protected storage (CWE-522). The flaw is remotely reachable without authentication and leaks sensitive credential data, which matters because those credentials can unlock further systems. The record does not specify the exact disclosure mechanism beyond the SQL credential disclosure reference title.
Impact
An unauthenticated attacker gains access to credentials, likely database or application credentials, enabling lateral movement or direct access to connected systems.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not state which endpoint or interface exposes the credentials.
Exploitation
Not listed in CISA KEV, but EPSS is 0.68779 (99.3rd percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade to ManageEngine EventLog Analyzer 10 Build 10000 or later, the stated fixed version.
- If upgrade is not immediate, restrict network access to the EventLog Analyzer interface to trusted management networks only.
- Rotate any credentials that may have been exposed by the affected instance, including database and service accounts.
- Audit logs for access to the vulnerable interface from untrusted sources.
Detection
- Monitor network logs for unauthenticated requests to EventLog Analyzer endpoints from unexpected hosts.
- Search application and web server logs for patterns matching the public exploit references.
- Alert on outbound authentication attempts using EventLog Analyzer service or database credentials from unusual sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2014/Nov/12 | ExploitMailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/70960 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/98539 | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2014/Nov/12 | ExploitMailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/70960 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/98539 | Third Party AdvisoryVDB Entry |
Track CVE-2014-6039 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-6039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.