An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Zoho Manageengine Adaudit Plus | — | Upgrade Zoho ManageEngine ADAudit Plus to the latest version | Dec 18, 2024 | Oct 17, 2023 |
| Zoho Manageengine Adselfservice Plus | — | Upgrade Zoho ManageEngine ADSelfService Plus to the latest version | Dec 18, 2024 | Aug 24, 2023 |
| Zoho Manageengine Pam360 | — | Upgrade Zoho ManageEngine PAM360 to the latest version | Jul 2, 2025 | Dec 1, 2023 |
| Zoho Manageengine Passwordmanager Pro | — | Upgrade Zoho ManageEngine PasswordManager Pro to the latest version | Dec 23, 2024 | Dec 13, 2023 |
| Zoho Manageengine Servicedesk Plus | — | Upgrade Zoho ManageEngine ServiceDesk Plus to the latest version | Dec 18, 2024 | Jun 28, 2023 |
| Zoho Manageengine Servicedesk Plus Msp | — | Upgrade Zoho ManageEngine ServiceDesk Plus MSP to the latest version | Jan 14, 2025 | Aug 10, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub