← Vulnerability feed

Vulnerability record · CVE-2017-16846 · published 16 November 2017

CVE-2017-16846: Zohocorp manageengine applications manager sql injection vulnerability

Zohocorp · Manageengine Applications Manager

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.

9.8 CVSS 3.0 Critical EPSS 17% · top 3.1% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-16846 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-24743Zohocorp manageengine applications manager vulnerabilityAn issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resou…EPSS 2.8%9.8CVE-2020-27995Zohocorp manageengine applications manager sql injection vulnerabilitySQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do templa…EPSS 8.8%9.8CVE-2020-15533Zohocorp manageengine applications manager sql injection vulnerabilityIn Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to un…EPSS 4.2%9.8CVE-2020-15394Zohocorp manageengine applications manager sql injection vulnerabilityThe REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to R…EPSS 7.9%9.8CVE-2019-19649Zohocorp manageengine applications manager sql injection vulnerabilityZoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the S…EPSS 9.5%9.8CVE-2019-11469Zohocorp manageengine applications manager sql injection vulnerabilityZoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user …EPSS 17%9.8CVE-2019-11448Zohocorp manageengine applications manager sql injection vulnerabilityAn issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the …EPSS 12%9.8CVE-2018-15168Zohocorp manageengine applications manager sql injection vulnerabilityA SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplayna…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2017-16846), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.