ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation and authentication bypass

CVE-2016-9489
8.8HIGH

Key Information

Status
Applications Manager
Vendor
CVE Published:
13 July 2018

Summary

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.

Affected Version(s)

Applications Manager = 12

Applications Manager = 13

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Thanks to Lukasz Juszczyk for reporting this vulnerability.
.