An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
History

Thu, 13 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database. An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2025-02-13T17:26:03.759Z

Reserved: 2023-11-13T15:10:28.339Z

Link: CVE-2023-6105

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-15T21:15:08.490

Modified: 2025-02-13T18:16:03.270

Link: CVE-2023-6105

cve-icon Redhat

No data.