CVE-2022-24447
MEDIUMZoho ManageEngine Key Manager Plus <6.2.00 - Info Disclosure
Title source: llmDescription
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.
References (3)
Core 3
Core References
Third Party Advisory
https://excellium-services.com/cert-xlm-advisory/cve-2022-24447/
Release Notes, Vendor Advisory
https://www.manageengine.com/key-manager/release-notes.html#6200
Various Sources
https://cds.thalesgroup.com/en/tcs-cert/CVE-2022-24447
Scores
CVSS v3
6.5
EPSS
0.0050
EPSS Percentile
66.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (3)
zohocorp/manageengine_key_manager_plus
6.0 6000 (3 CPE variants)
zohocorp/manageengine_key_manager_plus
6.1 6100 (5 CPE variants)
zohocorp/manageengine_key_manager_plus
< 5.9
Published
Mar 02, 2022
Tracked Since
Feb 18, 2026