CVE-2024-41140

HIGH

ManageEngine Applications Manager <= 174000 - Incorrect Authorization in Update User Function

Title source: llm
STIX 2.1

Description

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

Scores

CVSS v3 8.1
EPSS 0.0015
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (3)
zohocorp/manageengine_applications_manager 17.0 (9 CPE variants)
zohocorp/manageengine_applications_manager 17.3 (7 CPE variants)
zohocorp/manageengine_applications_manager < 17.0
Published Jan 29, 2025
Tracked Since Feb 18, 2026