4.3

CVE-2019-17112

An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4000
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4002
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4010
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4015
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4016
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4100
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4101
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4110
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4111
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4120
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4200
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4201
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4210
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4211
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.3 Update 4300
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.3 Update 4301
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.3 Update 4302
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5000
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5001
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5002
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5003
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5004
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5010
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5011
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.12% 0.795
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
MITRE 4.3 2.8 1.4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://excellium-services.com/cert-xlm-advisory/cve-2019-17112/
Third Party Advisory
https://www.manageengine.com/data-security/release-notes.html
Vendor Advisory
Release Notes