# Security Updates - CVE Details | ManageEngine Applications Manager ## CVE-2017-16850 ### SQL injection via the /showresource.do | Vulnerability Details | | |---|---| | Impact | **CVSS V3 rating:** 9.8 CRITICAL | | Reported | 16 November 2017 11/16/2017 | | Fixed | 11 December 2017 | | Affected Builds | Till Build 13520 | | Fixed in | Build 13530 | | Overview | SQL injection via the /showresource.do resourceid parameter. | | **Recommended Fix** | **Upgrade to Applications Manager Version 13530 or above.** | ### Description Applications Manager 13 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. We recommend that you upgrade to Applications Manager Version 13530 and above to fix this issue. ### Source and Acknowledgements Find out more about CVE-2017-16851 from the [CVE dictionary](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16850) and [NIST NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-16850). Other Resources: [https://code610.blogspot.com/2017/11/more-sql-injections-in-manageengine.html](https://code610.blogspot.com/2017/11/more-sql-injections-in-manageengine.html) ### Need Help? For clarification or corrections please contact our [support team](https://www.manageengine.com/products/applications_manager/support.html) or email us at [appmanager-support@manageengine.com](mailto:appmanager-support@manageengine.com)