Credentials management in ManageEngine Applications Manager - CVE-2016-9489

 

Credentials management in ManageEngine Applications Manager - CVE-2016-9489

Published: July 13, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36901
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2016-9489
CWE-ID: CWE-255
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Zoho Corporation
Affected software:
ManageEngine Applications Manager

Detailed vulnerability description

The vulnerability allows a remote authenticated user to execute arbitrary code.

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user's password.


How to mitigate CVE-2016-9489

Install update from vendor's website.

Sources