PT-2022-16704 · Zoho · Zoho Manageengine Admanager Plus

Dominique Righetto

·

Published

2022-03-02

·

Updated

2023-08-08

·

CVE-2022-24447

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine Key Manager Plus versions prior to 6200
Description An issue was discovered in the application where a service allows a user with the level Operator to access stored SSL certificates and associated key pairs during export.
Recommendations For versions prior to 6200, update to version 6200 or later to resolve the issue. As a temporary workaround, consider restricting access to the service that exposes SSL certificates and associated key pairs to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2022-24447

Affected Products

Zoho Manageengine Admanager Plus