CVE-2022-24447
02.03.2022, 15:15
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.Enginsight
Vendor | Product | Version |
---|---|---|
zohocorp | manageengine_key_manager_plus | 𝑥 ≤ 5.9 |
zohocorp | manageengine_key_manager_plus | 6.0:6000 |
zohocorp | manageengine_key_manager_plus | 6.0:6001 |
zohocorp | manageengine_key_manager_plus | 6.0:6002 |
zohocorp | manageengine_key_manager_plus | 6.1:6100 |
zohocorp | manageengine_key_manager_plus | 6.1:6150 |
zohocorp | manageengine_key_manager_plus | 6.1:6151 |
zohocorp | manageengine_key_manager_plus | 6.1:6160 |
zohocorp | manageengine_key_manager_plus | 6.1:6161 |
𝑥
= Vulnerable software versions