ZeroHour

CVE-2023-2291

PoC
CVSS 3.1
7.8 high
EPSS
<1%p55
Published
()
Modified
Description

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.

Vendors
zohocorp
Products
manageengine access manager plus, manageengine pam360, manageengine password manager pro
Weakness
CWE-798
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.