CVE-2025-9435

EUVD-2026-2355
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
ZohocorpCNA
5.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
Affected Products (NVD)
VendorProductVersion
zohocorpmanageengine_admanager_plus
𝑥
< 7.2
zohocorpmanageengine_admanager_plus
7.2:7200
zohocorpmanageengine_admanager_plus
7.2:7201
zohocorpmanageengine_admanager_plus
7.2:7202
zohocorpmanageengine_admanager_plus
7.2:7203
zohocorpmanageengine_admanager_plus
7.2:7210
zohocorpmanageengine_admanager_plus
7.2:7211
zohocorpmanageengine_admanager_plus
7.2:7212
zohocorpmanageengine_admanager_plus
7.2:7220
zohocorpmanageengine_admanager_plus
7.2:7221
zohocorpmanageengine_admanager_plus
7.2:7222
zohocorpmanageengine_admanager_plus
7.2:7223
zohocorpmanageengine_admanager_plus
7.2:7224
𝑥
= Vulnerable software versions