SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9491

ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications…

MEDIUM 4.9EPSS 2.56%

Does this matter?

Lower severity and a low EPSS score (2.56%). Track it; it rarely justifies an emergency change on its own.

Description

ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.

CVSS 3.0
4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
2.56% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-611, CWE-200
Affected
zohocorp/manageengine applications manager
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.