CVE Vulnerabilities

CVE-2016-9489

Published: Jul 13, 2018 | Modified: Oct 09, 2019
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like ADMIN. A user is also able to change properties of another user, e.g. change another users password.

Affected Software

Name Vendor Start Version End Version
Manageengine_applications_manager Zohocorp 12.0 (including) 12.0 (including)
Manageengine_applications_manager Zohocorp 13.0 (including) 13.0 (including)

References