CVE-2024-41140
Severity
6.5MEDIUM
EPSS
0.1%
top 65.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Description
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2