CVE-2024-41140: Improper Authorization
Published Jan 29, 2025
·Updated
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
Affected Software
19 affected components
ZohoCorp ManageEngine Applications Manager<174000
ZohoCorp ManageEngine Applications Manager<17.0
ZohoCorp ManageEngine Applications Manager>=17.1<17.3
ZohoCorp ManageEngine Applications Manager=17.0
ZohoCorp ManageEngine Applications Manager=17.0-build170000
ZohoCorp ManageEngine Applications Manager=17.0-build170001
ZohoCorp ManageEngine Applications Manager=17.0-build170002
ZohoCorp ManageEngine Applications Manager=17.0-build170003
ZohoCorp ManageEngine Applications Manager=17.0-build170004
ZohoCorp ManageEngine Applications Manager=17.0-build170005
ZohoCorp ManageEngine Applications Manager=17.0-build170006
ZohoCorp ManageEngine Applications Manager=17.0-build170007
ZohoCorp ManageEngine Applications Manager=17.3
ZohoCorp ManageEngine Applications Manager=17.3-build173000
ZohoCorp ManageEngine Applications Manager=17.3-build173100
ZohoCorp ManageEngine Applications Manager=17.3-build173200
ZohoCorp ManageEngine Applications Manager=17.3-build173300
ZohoCorp ManageEngine Applications Manager=17.3-build173301
ZohoCorp ManageEngine Applications Manager=17.3-build173302
Event History
Jan 29, 2025
CVE Published
via MITRE·11:14 AM
Data Sourced
via MITRE·11:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-41140?
CVE-2024-41140 is classified as a vulnerability with a potential impact on authorization controls.
2
How do I fix CVE-2024-41140?
To fix CVE-2024-41140, update your Zohocorp ManageEngine Applications Manager to version 174001 or later.
3
What versions of ManageEngine Applications Manager are affected by CVE-2024-41140?
Zohocorp ManageEngine Applications Manager versions 174000 and prior are affected by CVE-2024-41140.
4
What type of vulnerability is CVE-2024-41140?
CVE-2024-41140 is an authorization vulnerability in the update user function.
5
Who is the vendor responsible for CVE-2024-41140?
The vendor responsible for CVE-2024-41140 is Zohocorp.