CVE-2017-11738: Zohocorp ManageEngine Applications Manager

High severity, CVSS 8.1. EPSS: 4.1% chance of exploitation in the next 30 days.

In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.

Affected products

  • Zohocorp ManageEngine Applications Manager: version 13.1 only

Published 2019-05-23. Last modified 2026-06-17.