Lucene search

K
nvd[email protected]NVD:CVE-2023-38332
HistoryAug 04, 2023 - 6:15 p.m.

CVE-2023-38332

2023-08-0418:15:13
web.nvd.nist.gov
1
zoho manageengine admanager plus
sensitive information disclosure
vulnerability
authenticated users
account takeover

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

20.5%

Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user’s account via sensitive information disclosure.

Affected configurations

Nvd
Node
zohocorpmanageengine_admanager_plusRange<7.2
OR
zohocorpmanageengine_admanager_plusMatch7.27200
OR
zohocorpmanageengine_admanager_plusMatch7.27201
VendorProductVersionCPE
zohocorpmanageengine_admanager_plus*cpe:2.3:a:zohocorp:manageengine_admanager_plus:*:*:*:*:*:*:*:*
zohocorpmanageengine_admanager_plus7.2cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7200:*:*:*:*:*:*
zohocorpmanageengine_admanager_plus7.2cpe:2.3:a:zohocorp:manageengine_admanager_plus:7.2:7201:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

20.5%

Related for NVD:CVE-2023-38332