CVE-2016-9489: ManageEngine Applications Manager 12 and 13 is vulnerable to privilege escalation and authentication bypass
In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-9489?
CVE-2016-9489 is a vulnerability in ManageEngine Applications Manager 12 and 13 that allows an authenticated user to alter their own properties and the properties of other users, potentially granting higher privileges.
What is the severity of CVE-2016-9489?
CVE-2016-9489 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2016-9489?
An attacker with authenticated access can exploit CVE-2016-9489 by changing their group to one with higher privileges, such as 'ADMIN', or by changing the properties of another user.
Is there a fix for CVE-2016-9489?
Yes, a fix for CVE-2016-9489 is available in build 13200 of ManageEngine Applications Manager 12 and 13.
Where can I find more information about CVE-2016-9489?
You can find more information about CVE-2016-9489 on the seclists.org, manageengine.com, and securityfocus.com websites.