Information disclosure in ManageEngine Applications Manager - CVE-2025-6239
Published: July 22, 2025
ManageEngine Applications Manager
Detailed vulnerability description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due the application exposes encrypted database credentials of Applications Manager through Debug-Info HTML files in File/Directory monitor with content check enabled. A remote user can gain unauthorized access to sensitive information if such a File / Directory monitor is configured by the Administrator or Delegated Administrator.