Back
CVE-2016-9498
CRITICAL
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of system administrator, by exploiting this vulnerability an attacker gains highest privileges on the underlying operating system.
Published: Jul 13, 2018
Modified: Jun 17, 2026
CWE-502
CWE-502
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_applications_manager | 12.0 |
| zohocorp | manageengine_applications_manager | 13.0 |
GitHub Security Advisory GHSA-c3x4-w2jm-v6m5
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe...
References (6)
- http://seclists.org/fulldisclosure/2017/Apr/9 Mailing List, Third Party Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2016-9498.html Vendor Advisory
- https://www.securityfocus.com/bid/97394/ Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Apr/9 Mailing List, Third Party Advisory
- https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2016-9498.html Vendor Advisory
- https://www.securityfocus.com/bid/97394/ Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
22.01%
Top 3% most likely to be exploited
Threat Score
45.8 / 100
Data Sources
NVD
EPSS
GitHub