First published: Wed Apr 26 2023(Updated: )
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Access Manager Plus | =4.3-build4309 | |
Zohocorp ManageEngine PAM360 | ||
Zohocorp Manageengine Password Manager Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2291 is a vulnerability where static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP), ManageEngine Password Manager Pro, and ManageEngine PAM360.
The severity of CVE-2023-2291 is high with a CVSS score of 7.8.
CVE-2023-2291 affects ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360.
A malicious actor can exploit CVE-2023-2291 by using the static credentials to modify configuration data and escalate their permissions.
You can find more information about CVE-2023-2291 on the Tenable website at https://tenable.com/security/research/tra-2023-16.