CVE-2022-24446
01.03.2022, 02:15
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.Enginsight
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_key_manager_plus | 6.1.6 |
| zohocorp | manageengine_key_manager_plus | 6.1.6:build6100 |
| zohocorp | manageengine_key_manager_plus | 6.1.6:build6150 |
| zohocorp | manageengine_key_manager_plus | 6.1.6:build6151 |
| zohocorp | manageengine_key_manager_plus | 6.1.6:build6160 |
| zohocorp | manageengine_key_manager_plus | 6.1.6:build6161 |
𝑥
= Vulnerable software versions
References