CVE-2017-11557

MEDIUM

ZOHO ManageEngine Apps Mgr <12.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.

References (4)

Core 4
Core References
Vendor Advisory x_refsource_misc
http://manageengine.com
Vendor Advisory x_refsource_misc
https://www.manageengine.com/
Product x_refsource_misc
http://applications.com
Broken Link, Exploit, Third Party Advisory x_refsource_misc
https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18738

Scores

CVSS v3 5.3
EPSS 0.0086
EPSS Percentile 75.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
zohocorp/manageengine_applications_manager 12.3
Published May 23, 2019
Tracked Since Feb 18, 2026