An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: tenable

Published: 2023-11-15T20:57:47.981Z

Updated: 2023-11-15T20:57:47.981Z

Reserved: 2023-11-13T15:10:28.339Z


Link: CVE-2023-6105

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-11-15T21:15:08.490

Modified: 2024-06-26T20:15:14.867


Link: CVE-2023-6105

JSON object: View

cve-icon Redhat Information

No data.