IT

Tracker / CVE-2023-6105

CVE-2023-6105

Medium 5.5

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

Affected products and versions

zohocorp manageengine_access_manager_plus
zohocorp manageengine_access_manager_plus · … → 4.3
zohocorp manageengine_adaudit_plus
zohocorp manageengine_adaudit_plus · … → 7.2
zohocorp manageengine_admanager_plus
zohocorp manageengine_admanager_plus · … → 7.2
zohocorp manageengine_adselfservice_plus
zohocorp manageengine_adselfservice_plus · … → 6.3
zohocorp manageengine_analytics_plus · … → 5.3
zohocorp manageengine_appcreator · … → 2.0.0
zohocorp manageengine_application_control_plus · … → 11.2.2328.01
zohocorp manageengine_assetexplorer
zohocorp manageengine_assetexplorer · … → 7.0
zohocorp manageengine_browser_security_plus · … → 11.2.2328.01
zohocorp manageengine_cloud_security_plus
zohocorp manageengine_cloud_security_plus · … → 4.1
zohocorp manageengine_datasecurity_plus
zohocorp manageengine_datasecurity_plus · … → 6.1
zohocorp manageengine_device_control_plus · … → 11.2.2328.01
zohocorp manageengine_endpoint_central · … → 11.2.2322.01
zohocorp manageengine_endpoint_central_msp · … → 11.2.2322.01
zohocorp manageengine_endpoint_dlp_plus · … → 11.2.2328.01
zohocorp manageengine_exchange_reporter_plus
zohocorp manageengine_exchange_reporter_plus · … → 5.7
zohocorp manageengine_firewall_analyzer
zohocorp manageengine_firewall_analyzer · … → 12.5
zohocorp manageengine_firewall_analyzer · … → 12.7
zohocorp manageengine_log360_ueba
zohocorp manageengine_log360_ueba · … → 4.0
zohocorp manageengine_m365_manager_plus
zohocorp manageengine_m365_manager_plus · … → 4.5
zohocorp manageengine_m365_security_plus
zohocorp manageengine_m365_security_plus · … → 4.5
zohocorp manageengine_mobile_device_manager_plus
zohocorp manageengine_mobile_device_manager_plus · … → 10.1.2204.2
zohocorp manageengine_netflow_analyzer
zohocorp manageengine_netflow_analyzer · … → 12.5
zohocorp manageengine_netflow_analyzer · … → 12.7
zohocorp manageengine_network_configuration_manager
zohocorp manageengine_network_configuration_manager · … → 12.5
zohocorp manageengine_network_configuration_manager · … → 12.7
zohocorp manageengine_opmanager
zohocorp manageengine_opmanager · … → 12.5
zohocorp manageengine_opmanager · … → 12.7
zohocorp manageengine_oputils
zohocorp manageengine_oputils · … → 12.5
zohocorp manageengine_oputils · … → 12.7
zohocorp manageengine_os_deployer · … → 1.2.2331.1
zohocorp manageengine_pam360 · … → 5.7
zohocorp manageengine_password_manager_pro · … → 12.3
zohocorp manageengine_patch_connect_plus
zohocorp manageengine_patch_manager_plus · … → 11.2.2328.01
zohocorp manageengine_recoverymanager_plus
zohocorp manageengine_recoverymanager_plus · … → 6.0
zohocorp manageengine_remote_access_plus · … → 11.2.2328.01
zohocorp manageengine_remote_monitoring_and_management · … → 10.2.11
zohocorp manageengine_secure_gateway_server
zohocorp manageengine_secure_gateway_server · … → 9.0
zohocorp manageengine_servicedesk_plus
zohocorp manageengine_servicedesk_plus · … → 14.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References