← Vulnerability feed

Vulnerability record · CVE-2019-12196 · published 5 June 2019

CVE-2019-12196: Zoho ManageEngine NetFlow Analyzer SQL injection in compareReport

Zohocorp · Manageengine Netflow Analyzer

The compareReport endpoint in Zoho ManageEngine NetFlow Analyzer 12.3 fails to sanitize the DeviceID parameter, allowing SQL injection. An unauthenticated remote attacker can inject arbitrary SQL, which threatens the confidentiality, integrity and availability of the underlying database.

9.8 CVSS 3.0 Critical EPSS 69% · top 0.7% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a high EPSS score, makes this a top remediation priority.

What it is

The compareReport endpoint in Zoho ManageEngine NetFlow Analyzer 12.3 fails to sanitize the DeviceID parameter, allowing SQL injection. An unauthenticated remote attacker can inject arbitrary SQL, which threatens the confidentiality, integrity and availability of the underlying database.

Impact

An attacker can execute arbitrary SQL commands against the application database, potentially reading, modifying or deleting data and, depending on database privileges, affecting the host.

Attack surface

Reachable over the network through the /client/api/json/v2/nfareports/compareReport endpoint via the DeviceID parameter. The CVSS vector indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is high at roughly 0.69 (99th percentile), indicating substantial predicted exploitation activity.

What to do

  • Upgrade NetFlow Analyzer to the fixed build referenced in the vendor advisory (readme 124029) or later.
  • If patching is delayed, restrict network access to the compareReport API endpoint to trusted management hosts only.
  • Validate and parameterize the DeviceID input at the application layer and review other report endpoints for the same pattern.
  • Run the NetFlow Analyzer database with least-privilege credentials to limit the impact of successful injection.

Detection

  • Inspect web and proxy logs for requests to /client/api/json/v2/nfareports/compareReport with suspicious or malformed DeviceID values.
  • Alert on SQL metacharacters and keywords (quotes, UNION, SELECT, sleep, waitfor) in DeviceID parameters.
  • Monitor database logs for anomalous queries or errors originating from the NetFlow Analyzer application account.
  • Watch for unexpected outbound connections or data exfiltration from the NetFlow Analyzer host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12196 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38772ManageEngine OpManager and related products NMAP feature RCE via authenticated DB changesMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils) before speci…EPSS 78%analysed8.8CVE-2022-37024Zoho ManageEngine ITOM products allow authenticated database changes leading to RCEMultiple Zoho ManageEngine products (OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, OpUtils, Firewall Ana…EPSS 79%analysed8.6CVE-2023-47211ManageEngine OpManager uploadMib path traversal allows arbitrary file creationThe uploadMib function in ManageEngine OpManager 12.7.258 does not properly validate paths, so a crafted HTTP request carrying a malicious MIB file c…EPSS 47%analysed8.2CVE-2022-35404Zohocorp manageengine opmanager improper input validation vulnerabilityManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a serv…EPSS 2.9%7.8CVE-2019-12133Zohocorp manageengine analytics plus uncontrolled search path element vulnerabilityMultiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…EPSS 1.7%7.5CVE-2022-36923Zohocorp manageengine firewall analyzer improper access control vulnerabilityZoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 20…EPSS 7.1%7.5CVE-2018-12997Zohocorp firewall analyzer information exposure vulnerabilityIncorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before bui…EPSS 6.6%7.5CVE-2015-2959Zohocorp manageengine netflow analyzer improper access control vulnerabilityZoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive info…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2019-12196), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.