TCP: ManageEngine Applications Manager Apache Commons Collections Insecure Deserialization

An insecure deserialization vulnerability exists in ManageEngine Applications Manager. Successful exploitation can result in arbitrary code execution in the security context of the RMI service.

Extended Description

ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating system. As Application Manager's RMI registry is running with privileges of system administrator, by exploiting this vulnerability an attacker gains highest privileges on the underlying operating system.

Affected Products

Zohocorp manageengine_applications_manager

Short Name
APP:MISC:MANAGENGINE-DSRIALIZTN
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
Apache Applications CVE-2016-9498 Collections Commons Deserialization Insecure ManageEngine Manager
Release Date
04/24/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
Port
TCP/11099
False Positive
Unknown
Vendors

Zohocorp

CVSS Score

10.0

Found a potential security threat?