CVE-2025-9428

8.3

Zohocorp · ManageEngine Analytics Plus

Zohocorp ManageEngine Analytics Plus is vulnerable to authenticated SQL injection via the key update API, potentially allowing unauthorized database operations by an authenticated user.

Executive summary

An authenticated SQL injection vulnerability in Zohocorp ManageEngine Analytics Plus poses a high risk of database compromise and unauthorized data manipulation.

Vulnerability

The application is susceptible to SQL injection (CWE-89) within the key update API. This flaw requires the attacker to hold valid user credentials to interact with the vulnerable endpoint.

Business impact

Successful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary SQL commands against the backend database. Given the CVSS score of 8.3, this represents a high-severity risk that could lead to full data exfiltration, modification of sensitive business records, or potential service disruption.

Remediation

Immediate Action: Review the official ManageEngine security advisory for the availability of a patch and apply it immediately to all affected instances.

Proactive Monitoring: Monitor database query logs for unusual syntax, unexpected error patterns, or unauthorized access attempts originating from the key update API.

Compensating Controls: Implement strict database access controls and use a Web Application Firewall (WAF) to filter malicious SQL payloads directed at the application API.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the high CVSS severity and the critical nature of the ManageEngine platform, administrators should prioritize identifying all instances running version 6171 or earlier. Verify the status of the vendor patch and deploy it across the environment without delay to prevent unauthorized database interaction.

More Zohocorp CVEs

Sources