CVE-2016-9489 Vulnerability Details

  /     /     /  

CVE-2016-9489 Metadata Quick Info

CVE Published: 13/07/2018 | CVE Updated: 06/08/2024 | CVE Year: 2016
Source: certcc | Vendor: ManageEngine | Product: Applications Manager
Status : PUBLISHED

CVE-2016-9489 Description

In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another user, e.g. change another user\'s password.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-269
CWE Name: CWE-269
Source: ManageEngine

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).