CVE Vulnerabilities

CVE-2016-9489

Improper Privilege Management

Published: Jul 13, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like ADMIN. A user is also able to change properties of another user, e.g. change another users password.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_applications_managerZohocorp12.0 (including)12.0 (including)
Manageengine_applications_managerZohocorp13.0 (including)13.0 (including)

Potential Mitigations

References