CVE-2025-9435Path Traversal in Manageengine Admanager Plus

CWE-22Path Traversal4 documents4 sources
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 95.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:LExploitability: 2.1 | Impact: 3.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
CVEList
Path Traversal2026-01-13
GHSA
GHSA-85xf-m3mr-6pq2: Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module2026-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2025-9435 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-9435 — Path Traversal | cvebase