Vulnerability Description
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Applications Manager | 12.0 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2017/Apr/9Mailing ListThird Party Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/secuVendor Advisory
- https://www.securityfocus.com/bid/97394/Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2017/Apr/9Mailing ListThird Party Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/secuVendor Advisory
- https://www.securityfocus.com/bid/97394/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-9489?
CVE-2016-9489 is a vulnerability with a CVSS score of 8.8 (HIGH). In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher...
How severe is CVE-2016-9489?
CVE-2016-9489 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9489?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Applications Manager.