Impact
A permissions validation flaw in ZohoCorp ManageEngine Applications Manager allows a low‑privileged user to invoke administrator‑configured MBean actions on monitors outside the user’s assigned scope. This broken access control can be used to perform privileged operations such as modifying monitor settings, triggering tests, or collecting data that is normally restricted to administrators. The vulnerability is classified as CWE‑306.
Affected Systems
The affected product is Zohocorp ManageEngine Applications Manager, with vulnerable releases version 182200 and all earlier releases. No other vendors or products are listed as impacted.
Risk and Exploitability
The flaw has a CVSS score of 7.6 indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors include any environment in which a low‑privileged user can access the application and trigger MBean actions, such as internal networks or remote access to the management console. Because the flaw does not require elevated privileges to be exploited, the risk is that an attacker can elevate privileges or perform unauthorized administrative tasks within the application scope.
OpenCVE Enrichment