CVE-2022-24446: Medium severity manageengine key manager plus vulnerability
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24446?
CVE-2022-24446 is a vulnerability discovered in Zoho ManageEngine Key Manager Plus 6.1.6 that allows users with the level Operator to see all SSH servers and user information, even if no SSH server or user is associated with the operator.
How severe is CVE-2022-24446?
CVE-2022-24446 has a severity rating of 4.3, which is classified as medium severity.
What is the affected software version of CVE-2022-24446?
CVE-2022-24446 affects Zoho ManageEngine Key Manager Plus version 6.1.6.
How can I fix CVE-2022-24446?
To fix CVE-2022-24446, it is recommended to update Zoho ManageEngine Key Manager Plus to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2022-24446?
For more information about CVE-2022-24446, you can visit the following references: [Reference 1](https://excellium-services.com/cert-xlm-advisory/cve-2022-24446/) and [Reference 2](https://www.manageengine.com/key-manager/release-notes.html#6200).