Impact
A permission validation defect in ZohoCorp ManageEngine Applications Manager allows an authenticated user with low privileges to remove service monitors that fall outside the user’s authorized scope. The removal of these monitors disables visibility into the health and status of services that the user should not be able to delete, potentially masking outages, degrading alerting, and eroding confidence in monitoring data. This flaw does not provide a method for escalating privileges, but it does permit the attacker to erase critical monitoring artifacts and disrupt operational awareness.
Affected Systems
ZohoCorp ManageEngine Applications Manager versions 182000 and earlier are affected. The vulnerability resides in the monitoring module where delete operations are not properly constrained to the user’s designated scope. Any installation of these versions that permits low‑privileged users a delete capability is susceptible.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is categorized as moderate to high severity. EPSS data is not available, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the attacker must be authenticated as a low‑privileged user, suggesting a remote or local authenticated attack vector. The impact on availability and operational visibility is significant, as deleted monitors can lead to undetected downtime or configuration drift.
OpenCVE Enrichment