First published: Thu Jul 27 2017(Updated: )
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Eventlog Analyzer | =11.4 | |
Zohocorp Manageengine Eventlog Analyzer | =11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11686 is rated as a critical vulnerability due to its potential for unauthorized access to user passwords.
To fix CVE-2017-11686, upgrade to a patched version of Zoho ManageEngine Event Log Analyzer beyond 11.5.
The consequences of CVE-2017-11686 include the risk of credential theft and unauthorized access to sensitive systems.
CVE-2017-11686 affects ManageEngine Event Log Analyzer versions 11.4 and 11.5.
Yes, CVE-2017-11686 can be exploited remotely by attackers who can leverage XSS or sniff unencrypted network traffic.