CVE-2024-9097 Details
Description
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
An Insecure Direct Object Reference (IDOR) vulnerability has been identified in ManageEngine Endpoint Central versions prior to 11.3.2440.09. This vulnerability allows an attacker to manipulate usernames in the chat feature, potentially leading to unauthorized actions such as impersonating another user.
Users can upgrade to ManageEngine Endpoint Central versions 11.3.2440.09 or 11.3.2428.26, depending on their current build. Instructions for updating are available in the ManageEngine Endpoint Central knowledge base.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.manageengine.com/products/desktop-central/cve-2024-9097.html | ManageEngine | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | ManageEngine |
Affected Products
| Product | Versions |
|---|---|
| zohocorp manageengine endpoint central | >= 11.3.2428.01, < 11.3.2428.26 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ManageEngine |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 22, 2025 | Initial Analysis | [email protected] |
| Feb 5, 2025 | New CVE Received | ManageEngine |