4.3
CVE-2019-17112
- EPSS 2.12%
- Veröffentlicht 09.10.2019 20:15:23
- Zuletzt bearbeitet 21.11.2024 04:31:42
- Erkennungen
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4000
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4002
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4010
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4015
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.0 Update 4016
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4100
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4101
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4110
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4111
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.1 Update 4120
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4200
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4201
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4210
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.2 Update 4211
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.3 Update 4300
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.3 Update 4301
Zohocorp ≫ Manageengine Datasecurity Plus Version 4.3 Update 4302
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5000
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5001
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5002
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5003
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5004
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5010
Zohocorp ≫ Manageengine Datasecurity Plus Version 5.0 Update 5011
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.12% | 0.795 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
| MITRE | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
https://excellium-services.com/cert-xlm-advisory/cve-2019-17112/
https://www.manageengine.com/data-security/release-notes.html