Описание
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-24446
- https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24446
- https://excellium-services.com/cert-xlm-advisory
- https://excellium-services.com/cert-xlm-advisory/cve-2022-24446
- https://www.manageengine.com/key-manager
- https://www.manageengine.com/key-manager/release-notes.html#6200
Связанные уязвимости
CVSS3: 4.3
nvd
почти 4 года назад
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.