An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
2022-03-01T02:15:07.727
2025-05-30T16:15:29.740
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zohocorp | manageengine_key_manager_plus | 6.1.6 | Yes |
Application | zohocorp | manageengine_key_manager_plus | 6.1.6 | Yes |
Application | zohocorp | manageengine_key_manager_plus | 6.1.6 | Yes |
Application | zohocorp | manageengine_key_manager_plus | 6.1.6 | Yes |
Application | zohocorp | manageengine_key_manager_plus | 6.1.6 | Yes |
Application | zohocorp | manageengine_key_manager_plus | 6.1.6 | Yes |