Impact
Zohocorp's ManageEngine Applications Manager versions 182000 and earlier contain an input validation flaw that allows a user with low privileges to alter the application's proxy configuration. By changing the proxy settings, the attacker can redirect network traffic, potentially intercept credentials, bypass network controls, and elevate their operational scope. This flaw leads to a privilege escalation scenario where a non‑admin user gains broader control over the system's network communications, impacting confidentiality, integrity, and availability of the managed environment.
Affected Systems
The vulnerability affects Zohocorp ManageEngine Applications Manager, specifically all releases through version 182000. Users running these versions should verify their current installation against the vendor's security advisory.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw, and while an EPSS score is not provided, the lack of presence in the CISA KEV catalog suggests no widespread exploitation yet. The attack likely originates from the local user context; an authenticated low‑privileged account can change the proxy settings, triggering the escalation.
OpenCVE Enrichment