PT-2024-35177 · Zohocorp · Manageengine Analytics Plus
Mohamed Mekkawy
·
Published
2024-11-27
·
Updated
2024-12-11
·
CVE-2024-52323
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Zohocorp ManageEngine Analytics Plus versions below 6100
Description
The issue allows authenticated sensitive data exposure, enabling users to retrieve sensitive tokens associated with the org-admin account. This is related to the
getOAToken method, which is exposed and can lead to privilege escalation. The estimated number of potentially affected devices is not specified. There is no information about real-world incidents where this issue was exploited.Recommendations
For versions below 6100, upgrade to a version 6100 or later to mitigate the risk of sensitive data exposure. As a temporary workaround, consider restricting access to the
getOAToken method until a patch is available.Fix
Incorrect Default Permissions
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Manageengine Analytics Plus