CVE-2016-9491

UnknownEPSS 2.56%

Last modified

CVE-2016-9491 is a vulnerability of currently unknown severity. ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.. EPSS estimates a 2.56% chance of exploitation in the next 30 days.

Description

ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.

Metrics

EPSS Probability
2.56%

83.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ZohocorpManageengine Applications Manager12.0
ZohocorpManageengine Applications Manager13.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-9491?
ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored private keys, etc. By default Application Manager is running with administrative privileges, therefore it is possible to access every directory on the underlying operating system.
How severe is CVE-2016-9491?
Severity scoring for CVE-2016-9491 is pending analysis. The EPSS model estimates a 2.56% probability of exploitation in the next 30 days.
How do I fix CVE-2016-9491?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-9491?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST