First published: Tue Mar 01 2022(Updated: )
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Key Manager Plus | =6.1.6 | |
Zohocorp Manageengine Key Manager Plus | =6.1.6-build6100 | |
Zohocorp Manageengine Key Manager Plus | =6.1.6-build6150 | |
Zohocorp Manageengine Key Manager Plus | =6.1.6-build6151 | |
Zohocorp Manageengine Key Manager Plus | =6.1.6-build6160 | |
Zohocorp Manageengine Key Manager Plus | =6.1.6-build6161 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24446 is a vulnerability discovered in Zoho ManageEngine Key Manager Plus 6.1.6 that allows users with the level Operator to see all SSH servers and user information, even if no SSH server or user is associated with the operator.
CVE-2022-24446 has a severity rating of 4.3, which is classified as medium severity.
CVE-2022-24446 affects Zoho ManageEngine Key Manager Plus version 6.1.6.
To fix CVE-2022-24446, it is recommended to update Zoho ManageEngine Key Manager Plus to a version that is not affected by the vulnerability.
For more information about CVE-2022-24446, you can visit the following references: [Reference 1](https://excellium-services.com/cert-xlm-advisory/cve-2022-24446/) and [Reference 2](https://www.manageengine.com/key-manager/release-notes.html#6200).