← Vulnerability feed

Vulnerability record · CVE-2014-6043 · published 11 September 2014

CVE-2014-6043: Zohocorp manageengine eventlog analyzer permissions and access controls vulnerability

Zohocorp · Manageengine Eventlog Analyzer

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.

6.5 CVSS 2.0 Medium EPSS 13% · top 3.8% CWE-264 · Permissions and access controls
6.5CVSS 2.0 base score
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 12 tagged exploit
17 Jun 2026Last modified by NVD

Description

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-6043 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-28959Zohocorp manageengine eventlog analyzer path traversal vulnerabilityZoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to r…EPSS 17%9.8CVE-2020-24786Zohocorp manageengine adselfservice plus improper authentication vulnerabilityAn issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus befo…EPSS 13%8.8CVE-2019-19774Zohocorp manageengine eventlog analyzer vulnerabilityAn issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /…EPSS 13%8.1CVE-2023-35785Zohocorp manageengine ad360 improper authentication vulnerabilityZoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and b…EPSS 2.4%7.8CVE-2019-12133Zohocorp manageengine analytics plus uncontrolled search path element vulnerabilityMultiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…EPSS 1.7%7.5CVE-2014-6038ManageEngine EventLog Analyzer database information disclosureZoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose database information to unauthenticated remote users. The flaw is an inf…EPSS 73%analysed7.5CVE-2014-6039ManageEngine EventLog Analyzer credential disclosureManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 expose credentials through insufficiently protected storage (CWE-522). The flaw is r…EPSS 69%analysed7.5CVE-2015-7387ManageEngine EventLog Analyzer SQL injection via runQuery.do query parameterZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier fails to properly restrict the query parameter to event/runQuery.do, allowing an all…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2014-6043), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.