ManageEngine Applications Manager Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in ManageEngine Applications Manager, affecting versions through 178100. This vulnerability allows authenticated users to bypass command blacklists and execute sensitive commands with administrative privileges. The issue arises from improper validation in the 'execute program' action feature, where absolute paths can be used to circumvent security controls designed to prevent the execution of dangerous commands.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands with administrative rights, potentially compromising the security and integrity of the Applications Manager server.

Remediation

Users can update to ManageEngine Applications Manager version 178200 or later, or to versions 178001 through 178009. After updating, the 'execute program' actions will require super admin approval before being executed, adding a layer of security against unauthorized command execution.

Added: Nov 11, 2025, 2:18 PM
Updated: Nov 11, 2025, 2:18 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
4.4
remediation
8.3
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.