{"id":"CVE-2025-6239","title":"Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.","summary":"Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"vendor":"zohocorp","product":"manageengine_applications_manager","affected":["manageengine_applications_manager < 17.6","manageengine_applications_manager = 17.6"],"patched":["manageengine_applications_manager 17.6"],"published":"2025-10-21","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-6239","references":[{"url":"https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2025-6239.html","label":"0fc0942c-577d-436f-ae8e-945763c79b02"}],"tags":["nvd"],"epss":0.00957,"epssPercentile":0.60246,"ingestedAt":"2026-10-08T11:31:27.454Z","slug":"CVE-2025-6239","body":"## Overview\n\nZohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.\n\n## Affected\n\n- `manageengine_applications_manager < 17.6`\n- `manageengine_applications_manager = 17.6`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `manageengine_applications_manager 17.6`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}