CVE Vulnerabilities

CVE-2022-24447

Published: Mar 02, 2022 | Modified: Aug 08, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

Affected Software

Name Vendor Start Version End Version
Manageengine_key_manager_plus Zohocorp * 5.9 (including)
Manageengine_key_manager_plus Zohocorp 6.0-6000 (including) 6.0-6000 (including)
Manageengine_key_manager_plus Zohocorp 6.0-6001 (including) 6.0-6001 (including)
Manageengine_key_manager_plus Zohocorp 6.0-6002 (including) 6.0-6002 (including)
Manageengine_key_manager_plus Zohocorp 6.1-6100 (including) 6.1-6100 (including)
Manageengine_key_manager_plus Zohocorp 6.1-6150 (including) 6.1-6150 (including)
Manageengine_key_manager_plus Zohocorp 6.1-6151 (including) 6.1-6151 (including)
Manageengine_key_manager_plus Zohocorp 6.1-6160 (including) 6.1-6160 (including)
Manageengine_key_manager_plus Zohocorp 6.1-6161 (including) 6.1-6161 (including)

References