« Back to list

CVE-2024-9459

Status: AnalyzedHigh (8.8)—

Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

SQL injection autenticada (CWE-89) en módulo de reportes permite consultar datos sensibles (C:H) y modificar datos en BD (I:H). Requiere PR:L (autenticación), acceso de red sin privilegios de red: T1210.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2024-9459",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-9459",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-05T16:22:14.072305Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "affectedData": [
        {
          "vendor": "ManageEngine",
          "product": "Exchange Reporter Plus",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5719",
              "versionType": "5719"
            }
          ],
          "collectionURL": "https://www.manageengine.com/products/exchange-reports/",
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:*:*:*:*:*:*:*:*"
          ],
          "vendor": "zohocorp",
          "product": "manageengine_exchange_reporter_plus",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5719",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-11-05T06:15:06.057",
  "references": [
    {
      "url": "https://www.manageengine.com/products/exchange-reports/advisory/CVE-2024-9459.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0fc0942c-577d-436f-ae8e-945763c79b02",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module."
    },
    {
      "lang": "es",
      "value": "Las versiones 5718 y anteriores de Zohocorp ManageEngine Exchange Reporter Plus son vulnerables a la inyección SQL autenticada en el módulo de informes."
    }
  ],
  "lastModified": "2026-06-17T08:24:36.580",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3DA0580F-8167-450E-A1E9-0F1F7FC7E2C9",
              "versionEndExcluding": "5.7"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FC399C6-4299-4744-9FC5-13CFE7478164"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5700:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E913F3D6-9F94-4130-94FF-37F4D81BAEF4"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5701:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34D23B58-2BB8-40EE-952C-1595988335CC"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5702:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "322920C4-4487-4E44-9C40-2959F478A4FA"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5703:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AD735B9-2CE2-46BA-9A14-A22E3FE21C6D"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5704:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "014DB85C-DB28-4EBB-971A-6F8F964CE6FE"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5705:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5E9B0013-ABF8-4616-BC92-15DF9F5CB359"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5706:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B744F32-FD43-47B8-875C-6777177677CD"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5707:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F1BB6EEA-2BAA-4C48-8DA8-1E87B3DE611F"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5708:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3012C17-87F5-4FFD-B67B-BEFF2A390613"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5709:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E33D368-2D81-4C7E-9405-7C0A86E97217"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5710:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AA9384F-6401-4495-B558-23E5A7A7528C"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5711:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E492F955-0734-4AE4-A59F-572ADF0CFE75"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5712:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11B71FFC-FD2E-4F84-BB1E-55BCA5B51099"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5713:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "531AFEFB-BBE6-42B2-8D37-B4098324AA87"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5714:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01F80C71-110D-4776-B13F-08FCDE125B81"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5715:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A6D8AAD-49B9-4216-9A81-A449A5D5549C"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5717:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "852DBCE6-B926-4B5B-B8C2-86569355153D"
            },
            {
              "criteria": "cpe:2.3:a:zohocorp:manageengine_exchange_reporter_plus:5.7:5718:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5E6DB9D-4919-4827-A9F6-1DFCB78F4004"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "0fc0942c-577d-436f-ae8e-945763c79b02"
}