User Information Exposure in Zoho ManageEngine Key Manager Plus
CVE-2022-24446
4.3MEDIUM
What is CVE-2022-24446?
A vulnerability in Zoho ManageEngine Key Manager Plus version 6.1.6 allows an Operator-level user to access sensitive information about all SSH servers and associated users, regardless of whether they officially relate to the user. This can lead to unauthorized visibility of server configurations and user credentials, presenting a significant risk for organizations relying on this product for secure key management.