RULE(RULE ID:311621)

Rule General Information
Release Date: 2015-04-16
Rule Name: Manageengine Eventlog Analyzer Hostdetails Information Disclosure Vulnerability (CVE-2014-6039)
Severity:
CVE ID:
Rule Protection Details
Description: An information disclosure vulnerability was found in ManageEngine EventLog Analyzer. The vulnerability is caused by failing to restrict access to confidential data in the HostDataServlet servlet.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Other Unix, Linux
Reference: SecurityFocusBID:70960
https://exchange.xforce.ibmcloud.com/vulnerabilities/98539
https://packetstormsecurity.com/files/128996/ManageEngine-EventLog-Analyzer-SQL-Credential-Disclosure.html
http://seclists.org/fulldisclosure/2014/Nov/12
Solutions
No information about possible solutions is published. Please use an alternative product to substitude the affected software.