CVE-2024-41140 Details
Description
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
A privilege escalation vulnerability has been identified in ManageEngine Applications Manager versions through 174000. The issue arises from incorrect authorization in the 'update user' function, allowing delegated admins to gain unauthorized admin access by modifying user group parameters via the API.
Users can update to ManageEngine Applications Manager version 174000 or any of the specified fixed versions. Instructions for updating are available on the ManageEngine Applications Manager service packs page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 29, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2024-41140.html | ManageEngine | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| zohocorp manageengine applications manager | < 17.0 >= 17.1, < 17.3 17.0 - 17.0 build170000 17.0 build170001 17.0 build170002 17.0 build170003 17.0 build170004 17.0 build170005 17.0 build170006 17.0 build170007 17.3 - 17.3 build173000 17.3 build173100 17.3 build173200 17.3 build173300 17.3 build173301 17.3 build173302 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2025 | Initial Analysis | [email protected] |
| Jan 29, 2025 | New CVE Received | ManageEngine |