First published: Wed Feb 05 2025(Updated: )
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Unified Endpoint Management Suite | <11.3.2440.09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9097 is classified as a medium severity vulnerability due to its exploitation potential without requiring authentication.
To mitigate CVE-2024-9097, upgrade ManageEngine Endpoint Central to version 11.3.2440.09 or later.
An IDOR vulnerability, like in CVE-2024-9097, allows unauthorized changes to resources—in this case, an attacker's ability to modify usernames in the chat.
ManageEngine Endpoint Central versions prior to 11.3.2440.09 are affected by CVE-2024-9097.
Yes, CVE-2024-9097 can be exploited without authentication, making it easier for attackers to manipulate the chat usernames.