SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-41140

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

MEDIUM 6.5EPSS 0.93%

Does this matter?

Lower severity and a low EPSS score (0.93%). Track it; it rarely justifies an emergency change on its own.

Description

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
EPSS
0.93% probability · 59th percentile
CISA KEV
Not listed
Weakness
CWE-863
Affected
zohocorp/manageengine applications manager
Source
0fc0942c-577d-436f-ae8e-945763c79b02

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.