Exposed Configuration File Vulnerability in Zoho ManageEngine DataSecurity Plus
CVE-2019-17112

4.3MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
9 October 2019

What is CVE-2019-17112?

A vulnerability in Zoho ManageEngine DataSecurity Plus allows users with 'Operator' access level to access the configuration file of the mail server. This exposure, which does not include the server password, could potentially lead to unauthorized access and misuse of sensitive email server settings, impacting the overall security posture of affected organizations.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.