| Vulnerability Details | |
|---|---|
| Severity | High |
| CVE ID | CVE-2025-9223 |
| Affected software versions | Version 178100 and below |
| Fixed Version | Version 178200 and above Version 178001 to 178009 |
| Fixed On | 22 October 2025 |
Authenticated users could execute blacklisted sensitive commands with administrative privileges on Applications Manager servers, potentially compromising system security and integrity.
Applications Manager version 178200 (refer above for other fixed versions) and above requires super admin approval for creating/updating execute program actions. New actions remain disabled pending approval, preventing unauthorized command execution.
Update your Applications Manager instance to the latest build using the service pack.
Find out more about CVE-2025-9223 from the CVE Directory and NIST NVD.
Johan
For clarification or corrections please contact our support team or email us at appmanager-support@manageengine.com
It allows us to track crucial metrics such as response times, resource utilization, error rates, and transaction performance. The real-time monitoring alerts promptly notify us of any issues or anomalies, enabling us to take immediate action.
Reviewer Role: Research and Development