CVE Vulnerabilities

CVE-2023-6105

Published: Nov 15, 2023 | Modified: Dec 28, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

Affected Software

Name Vendor Start Version End Version
Manageengine_analytics_plus Zohocorp * 5.3 (excluding)
Manageengine_appcreator Zohocorp * 2.0.0 (excluding)
Manageengine_application_control_plus Zohocorp * 11.2.2328.01 (excluding)
Manageengine_browser_security_plus Zohocorp * 11.2.2328.01 (excluding)
Manageengine_device_control_plus Zohocorp * 11.2.2328.01 (excluding)
Manageengine_endpoint_central Zohocorp * 11.2.2322.01 (excluding)
Manageengine_endpoint_central_msp Zohocorp * 11.2.2322.01 (excluding)
Manageengine_endpoint_dlp_plus Zohocorp * 11.2.2328.01 (excluding)
Manageengine_mobile_device_manager_plus Zohocorp * 10.1.2204.2 (excluding)
Manageengine_mobile_device_manager_plus Zohocorp 10.1.2207.4 (including) 10.1.2207.4 (including)
Manageengine_os_deployer Zohocorp * 1.2.2331.1 (excluding)
Manageengine_patch_manager_plus Zohocorp * 11.2.2328.01 (excluding)
Manageengine_remote_access_plus Zohocorp * 11.2.2328.01 (excluding)
Manageengine_remote_monitoring_and_management Zohocorp * 10.2.11 (excluding)
Manageengine_vulnerability_manager_plus Zohocorp * 11.2.2328.01 (excluding)

References