ManageEngine EventLog Analyzer CVE-2014-6039 Password Disclosure Vulnerability
BID:70960
CVE-2014-6039 |Info
ManageEngine EventLog Analyzer CVE-2014-6039 Password Disclosure Vulnerability
| Bugtraq ID: | 70960 |
| Class: | Design Error |
| CVE: |
CVE-2014-6039 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 05 2014 12:00AM |
| Updated: | Nov 05 2014 12:00AM |
| Credit: | Pedro Ribeiro |
| Vulnerable: |
ManageEngine Eventlog Analyzer 9.9 Build 9002 ManageEngine Eventlog Analyzer 9.9 ManageEngine Eventlog Analyzer 8.6 ManageEngine Eventlog Analyzer 7 |
| Not Vulnerable: | |
Discussion
ManageEngine EventLog Analyzer CVE-2014-6039 Password Disclosure Vulnerability
EventLog Analyzer is prone to a password-disclosure vulnerability.
An attacker can exploit this issue to disclose sensitive information. Information obtained may lead to further attacks.
EventLog Analyzer 7 through 9.9 build 9002 are vulnerable.
EventLog Analyzer is prone to a password-disclosure vulnerability.
An attacker can exploit this issue to disclose sensitive information. Information obtained may lead to further attacks.
EventLog Analyzer 7 through 9.9 build 9002 are vulnerable.
Exploit / POC
ManageEngine EventLog Analyzer CVE-2014-6039 Password Disclosure Vulnerability
An attacker can exploit this issue using a browser.
The following metasploit module is available:
An attacker can exploit this issue using a browser.
The following metasploit module is available:
Solution / Fix
ManageEngine EventLog Analyzer CVE-2014-6039 Password Disclosure Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
ManageEngine EventLog Analyzer CVE-2014-6039 Password Disclosure Vulnerability
References:
References:
- Event LogAnalyzer Homepage (ManageEngine)
- [The ManageOwnage Series, part VI]: 0day database info and superuser credential (SecLists.Org)