User Information Exposure in Zoho ManageEngine Key Manager Plus
CVE-2022-24446
4.3MEDIUM
What is CVE-2022-24446?
A vulnerability in Zoho ManageEngine Key Manager Plus version 6.1.6 allows an Operator-level user to access sensitive information about all SSH servers and associated users, regardless of whether they officially relate to the user. This can lead to unauthorized visibility of server configurations and user credentials, presenting a significant risk for organizations relying on this product for secure key management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved