CVE Vulnerabilities

CVE-2023-2291

Published: Apr 26, 2023 | Modified: Feb 03, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.

Affected Software

NameVendorStart VersionEnd Version
Manageengine_access_manager_plusZohocorp4.3-build4309 (including)4.3-build4309 (including)
Manageengine_pam360Zohocorp**
Manageengine_password_manager_proZohocorp**

References