Vulnerability Details CVE-2022-24447
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.8%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2022-24447
-
cpe:2.3:a:zohocorp:manageengine_key_manager_plus:5.6
-
cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0
-
cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1