CVE-2019-17112
09.10.2019, 20:15
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).Enginsight| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_datasecurity_plus | 4.0:4000 |
| zohocorp | manageengine_datasecurity_plus | 4.0:4002 |
| zohocorp | manageengine_datasecurity_plus | 4.0:4010 |
| zohocorp | manageengine_datasecurity_plus | 4.0:4015 |
| zohocorp | manageengine_datasecurity_plus | 4.0:4016 |
| zohocorp | manageengine_datasecurity_plus | 4.1:4100 |
| zohocorp | manageengine_datasecurity_plus | 4.1:4101 |
| zohocorp | manageengine_datasecurity_plus | 4.1:4110 |
| zohocorp | manageengine_datasecurity_plus | 4.1:4111 |
| zohocorp | manageengine_datasecurity_plus | 4.1:4120 |
| zohocorp | manageengine_datasecurity_plus | 4.2:4200 |
| zohocorp | manageengine_datasecurity_plus | 4.2:4201 |
| zohocorp | manageengine_datasecurity_plus | 4.2:4210 |
| zohocorp | manageengine_datasecurity_plus | 4.2:4211 |
| zohocorp | manageengine_datasecurity_plus | 4.3:4300 |
| zohocorp | manageengine_datasecurity_plus | 4.3:4301 |
| zohocorp | manageengine_datasecurity_plus | 4.3:4302 |
| zohocorp | manageengine_datasecurity_plus | 5.0:5000 |
| zohocorp | manageengine_datasecurity_plus | 5.0:5001 |
| zohocorp | manageengine_datasecurity_plus | 5.0:5002 |
| zohocorp | manageengine_datasecurity_plus | 5.0:5003 |
| zohocorp | manageengine_datasecurity_plus | 5.0:5004 |
| zohocorp | manageengine_datasecurity_plus | 5.0:5010 |
| zohocorp | manageengine_datasecurity_plus | 5.0:5011 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration