CVE-2012-1063: ManageEngine Applications Manager
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to fault/AlarmView.do or (2) period parameter to showHistoryData.do.
Affected products
- ManageEngine Applications Manager: version 10.0 only; version 10.1 only; version 10.2 only; version 10.3 only; version 9.1 only; version 9.2 only; …
Published 2012-02-14. Last modified 2026-06-16.