PT-2022-16703 · Zoho · Zoho Manageengine Admanager Plus
Dominique Righetto
·
Published
2022-03-01
·
Updated
2023-08-08
·
CVE-2022-24446
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Key Manager Plus version 6.1.6
Description
An issue was discovered where a user with the level Operator can see all SSH servers and user information, even if no SSH server or user is associated with the operator.
Recommendations
For Zoho ManageEngine Key Manager Plus version 6.1.6, consider restricting access to sensitive information for Operator-level users until a patch is available.
As a temporary workaround, consider limiting the visibility of SSH servers and user information to only those associated with each Operator.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoho Manageengine Admanager Plus