CVE-2025-6239: Information disclosure
Published Oct 21, 2025
·Updated
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
Affected Software
10 affected components
Zoho ManageEngine Applications Manager<=176800
Zohocorp ManageEngine Applications Manager<17.6
Zohocorp ManageEngine Applications Manager=17.6
Zohocorp ManageEngine Applications Manager=17.6-build176100
Zohocorp ManageEngine Applications Manager=17.6-build176200
Zohocorp ManageEngine Applications Manager=17.6-build176300
Zohocorp ManageEngine Applications Manager=17.6-build176500
Zohocorp ManageEngine Applications Manager=17.6-build176600
Zohocorp ManageEngine Applications Manager=17.6-build176700
Zohocorp ManageEngine Applications Manager=17.6-build176800
Event History
Oct 21, 2025
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-6239?
The severity of CVE-2025-6239 is classified as high due to the potential for information disclosure.
2
How do I fix CVE-2025-6239?
To fix CVE-2025-6239, upgrade Zoho ManageEngine Applications Manager to a version higher than 176800.
3
What kind of vulnerability is CVE-2025-6239?
CVE-2025-6239 is an information disclosure vulnerability affecting the File/Directory monitoring feature.
4
Who is affected by CVE-2025-6239?
CVE-2025-6239 affects users of Zoho ManageEngine Applications Manager versions 176800 and below.
5
What are the potential impacts of CVE-2025-6239?
The potential impacts of CVE-2025-6239 include unauthorized access to sensitive file or directory information.