CVE-2024-41140

Zohocorp ManageEngine Applications Manager versions174000 and prior are vulnerable to the incorrect authorization in the update user function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
ManageEngineCNA
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
VendorProductVersion
zohocorpmanageengine_applications_manager
𝑥
< 17.0
zohocorpmanageengine_applications_manager
17.1 ≤
𝑥
< 17.3
zohocorpmanageengine_applications_manager
17.0
zohocorpmanageengine_applications_manager
17.0:build170000
zohocorpmanageengine_applications_manager
17.0:build170001
zohocorpmanageengine_applications_manager
17.0:build170002
zohocorpmanageengine_applications_manager
17.0:build170003
zohocorpmanageengine_applications_manager
17.0:build170004
zohocorpmanageengine_applications_manager
17.0:build170005
zohocorpmanageengine_applications_manager
17.0:build170006
zohocorpmanageengine_applications_manager
17.0:build170007
zohocorpmanageengine_applications_manager
17.3
zohocorpmanageengine_applications_manager
17.3:build173000
zohocorpmanageengine_applications_manager
17.3:build173100
zohocorpmanageengine_applications_manager
17.3:build173200
zohocorpmanageengine_applications_manager
17.3:build173300
zohocorpmanageengine_applications_manager
17.3:build173301
zohocorpmanageengine_applications_manager
17.3:build173302
𝑥
= Vulnerable software versions