CVE-2022-24446

An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
zohocorpmanageengine_key_manager_plus
6.1.6
zohocorpmanageengine_key_manager_plus
6.1.6:build6100
zohocorpmanageengine_key_manager_plus
6.1.6:build6150
zohocorpmanageengine_key_manager_plus
6.1.6:build6151
zohocorpmanageengine_key_manager_plus
6.1.6:build6160
zohocorpmanageengine_key_manager_plus
6.1.6:build6161
𝑥
= Vulnerable software versions