CVE-2024-41140 – Zohocorp ManageEngine Applications Manager Authorization Bypass Vulnerability

The following table lists the changes that have been made to the CVE-2024-41140 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received by 0fc0942c-577d-436f-ae8e-945763c79b02

    Jan. 29, 2025

    Action Type Old Value New Value
    Added Description Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
    Added CWE CWE-863
    Added Reference https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2024-41140.html

نوشته های مشابه