CVE-2020-11946

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
zohocorpmanageengine_opmanager
12.5:build125000
zohocorpmanageengine_opmanager
12.5:build125002
zohocorpmanageengine_opmanager
12.5:build125100
zohocorpmanageengine_opmanager
12.5:build125101
zohocorpmanageengine_opmanager
12.5:build125102
zohocorpmanageengine_opmanager
12.5:build125108
zohocorpmanageengine_opmanager
12.5:build125110
zohocorpmanageengine_opmanager
12.5:build125111
zohocorpmanageengine_opmanager
12.5:build125112
zohocorpmanageengine_opmanager
12.5:build125113
zohocorpmanageengine_opmanager
12.5:build125114
zohocorpmanageengine_opmanager
12.5:build125116
zohocorpmanageengine_opmanager
12.5:build125117
zohocorpmanageengine_opmanager
12.5:build125118
𝑥
= Vulnerable software versions