LOW · 3.5

CVE-2024-9097

ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

Vulnerability Description

ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

CVSS Score

3.5

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ZohocorpManageengine Endpoint Central>= 11.3.2428.01, < 11.3.2428.26

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-9097?

CVE-2024-9097 is a vulnerability with a CVSS score of 3.5 (LOW). ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

How severe is CVE-2024-9097?

CVE-2024-9097 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-9097?

Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Endpoint Central.