List of security vulnerabilities fixed in Analytics Plus on-premise

This page contains a list of all security vulnerabilities fixed in Analytics Plus on-premise along with their CVE ID and the fixed build number. To report vulnerabilities in ManageEngine products, head to ManageEngine's Security Response Center.

 
CVE ID/ZVE IDSynopsisSeverityAffected BuildsFixed in
CVE-2024-9100A Local File Inclusion (LFI) vulnerability has been discovered in Analytics Plus on-premise. This vulnerability enables an authenticated user to read arbitrary files from the server's file system through HSQLDB queries, potentially exposing sensitive information.MediumAnalytics Plus on-Premise builds below 5410Build 5410
CVE-2024-52323A Sensitive Data Exposure vulnerability has been identified in Analytics Plus on-premise, allowing an authenticated user to retrieve sensitive tokens associated to the org-admin account. This could potentially lead to unintended privilege escalation.HighAnalytics Plus on-premise builds below 6100Build 6100
CVE-2025-1724A vulnerability has been discovered in Analytics Plus on-premise, which allows unauthorized access to authenticated AD user accounts. This could potentially lead to the unauthorized exposure of user information.HighAll Analytics Plus on-premise Windows builds below 6130Build 6130
CVE-2025-8324An unauthenticated SQL injection vulnerability (CVE-2025-8324) has been identified in Analytics Plus on-premise. This vulnerability could allow attackers to execute arbitrary SQL queries due to insufficient input validation.CriticalAnalytics Plus on-premise builds below 6170Build 6171
CVE-2025-9428A SQL injection vulnerability (CVE-2025-9428) has been identified in Analytics Plus on-Premise. This vulnerability could allow an authenticated user to execute arbitrary SQL queries due to insufficient input validation.HighAnalytics Plus on-premise builds below 6171Build 6200