First published: Mon Mar 09 2020(Updated: )
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Password Manager Pro | =8.3-build8303 | |
ManageEngine Password Manager Pro | =8.4-build8400 | |
ManageEngine Password Manager Pro | =8.4-build8401 | |
ManageEngine Password Manager Pro | =8.4-build8402 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1159 is a vulnerability in ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400, 8401, 8402) that allows underprivileged users to obtain sensitive information via a vulnerable hidden service.
CVE-2016-1159 has a severity rating of 6.5 (Medium).
Underprivileged users can exploit CVE-2016-1159 to obtain sensitive information (entry password history) via a vulnerable hidden service in ZOHO Password Manager Pro 8.3.0 (Build 8303) and 8.4.0 (Build 8400, 8401, 8402).
ZOHO Password Manager Pro 8.3.0 (Build 8303) and 8.4.0 (Build 8400, 8401, 8402) are affected by CVE-2016-1159.
Yes, fixes for CVE-2016-1159 are available on the ZOHO Password Manager Pro website.