peter bassill · operator
$ cve CVE-2014-3997 JSON

CVE-2014-3997 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 13.1% (pctl 96)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS13.05% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2014-12-05
Last modified2026-06-17

Affected (2)

VendorProduct
zohocorpmanageengine it360
zohocorpmanageengine password manager pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD