Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jvx-3h5f-w2j7

Опубликовано: 15 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

EPSS

Процентиль: 25%
0.00084
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.5
nvd
около 2 лет назад

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

EPSS

Процентиль: 25%
0.00084
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200