ManageEngine Applications Manager
cpe:2.3:a:zohocorp:manageengine_applications_manager:*:*:*:*:*:*:*
- <= 173900
A privilege escalation vulnerability has been identified in ManageEngine Applications Manager versions through 174000. The issue arises from incorrect authorization in the 'update user' function, allowing delegated admins to gain unauthorized admin access by modifying user group parameters via the API.
Exploitation of this vulnerability allows users with delegated admin privileges to gain full admin access.
Users can update to ManageEngine Applications Manager version 174000 or any of the specified fixed versions. Instructions for updating are available on the ManageEngine Applications Manager service packs page.