CVE-2016-9491
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications…
Does this matter?
Lower severity and a low EPSS score (2.56%). Track it; it rarely justifies an emergency change on its own.
Description
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.56% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611, CWE-200
- Affected
- zohocorp/manageengine applications manager
- Source
- cret@cert.org
References
- http://seclists.org/fulldisclosure/2017/Apr/9Mailing List, Third Party Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2016-9491.htmlVendor Advisory
- https://www.securityfocus.com/bid/97394/Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Apr/9Mailing List, Third Party Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2016-9491.htmlVendor Advisory
- https://www.securityfocus.com/bid/97394/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.