An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Manageengine_key_manager_plus | Zohocorp | 6.1.6 (including) | 6.1.6 (including) |
Manageengine_key_manager_plus | Zohocorp | 6.1.6-build6100 (including) | 6.1.6-build6100 (including) |
Manageengine_key_manager_plus | Zohocorp | 6.1.6-build6150 (including) | 6.1.6-build6150 (including) |
Manageengine_key_manager_plus | Zohocorp | 6.1.6-build6151 (including) | 6.1.6-build6151 (including) |
Manageengine_key_manager_plus | Zohocorp | 6.1.6-build6160 (including) | 6.1.6-build6160 (including) |
Manageengine_key_manager_plus | Zohocorp | 6.1.6-build6161 (including) | 6.1.6-build6161 (including) |