Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:MISC:MANAGENGINE-DSRIALIZTN

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

ManageEngine Applications Manager Apache Commons Collections Insecure Deserialization

Release Date

2017/04/23

Update Number

2873

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

TCP: ManageEngine Applications Manager Apache Commons Collections Insecure Deserialization


An insecure deserialization vulnerability exists in ManageEngine Applications Manager. Successful exploitation can result in arbitrary code execution in the security context of the RMI service.

Extended Description

ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of system administrator, by exploiting this vulnerability an attacker gains highest privileges on the underlying operating system.

Affected Products

  • Zohocorp manageengine_applications_manager 12.0
  • Zohocorp manageengine_applications_manager 13.0

References

  • CVE: CVE-2016-9498

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out