CVE-2019-17112

An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
mitreCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AC:L/AV:N/A:N/C:L/I:N/PR:L/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
zohocorpmanageengine_datasecurity_plus
4.0:4000
zohocorpmanageengine_datasecurity_plus
4.0:4002
zohocorpmanageengine_datasecurity_plus
4.0:4010
zohocorpmanageengine_datasecurity_plus
4.0:4015
zohocorpmanageengine_datasecurity_plus
4.0:4016
zohocorpmanageengine_datasecurity_plus
4.1:4100
zohocorpmanageengine_datasecurity_plus
4.1:4101
zohocorpmanageengine_datasecurity_plus
4.1:4110
zohocorpmanageengine_datasecurity_plus
4.1:4111
zohocorpmanageengine_datasecurity_plus
4.1:4120
zohocorpmanageengine_datasecurity_plus
4.2:4200
zohocorpmanageengine_datasecurity_plus
4.2:4201
zohocorpmanageengine_datasecurity_plus
4.2:4210
zohocorpmanageengine_datasecurity_plus
4.2:4211
zohocorpmanageengine_datasecurity_plus
4.3:4300
zohocorpmanageengine_datasecurity_plus
4.3:4301
zohocorpmanageengine_datasecurity_plus
4.3:4302
zohocorpmanageengine_datasecurity_plus
5.0:5000
zohocorpmanageengine_datasecurity_plus
5.0:5001
zohocorpmanageengine_datasecurity_plus
5.0:5002
zohocorpmanageengine_datasecurity_plus
5.0:5003
zohocorpmanageengine_datasecurity_plus
5.0:5004
zohocorpmanageengine_datasecurity_plus
5.0:5010
zohocorpmanageengine_datasecurity_plus
5.0:5011
𝑥
= Vulnerable software versions