Published:2016/07/01 Last Updated:2016/07/01
JVNVU#95113461
ManageEngine Password Manager Pro vulnerable to cross-site request forgery
Overview
ManageEngine Password Manager Pro contains a cross-site request forgery vulnerability.
Products Affected
- Password Manager Pro versions prior to 8.5 (Build 8500)
Description
ManageEngine Password Manager Pro provided by Zoho Corporation contains a cross-site request forgery vulnerability (CWE-352).
Impact
If a user accesses a malicious URL while logged in, unintended operations such as adding a new user account or deleting an existing account may be performed.
Solution
Update the Software
This vulnerability has been addressed in Password Manager Pro 8.5 (Build 8500).
Update to the latest version according to the information provided by the developer.
Vendor Status
Vendor | Link |
Zoho Corporation | ManageEngine Password Manager Pro - Issues Fixed |
ManageEngine Password Manager Pro - Release Notes |
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Base Score:
6.3
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
CVSS v2
AV:N/AC:H/Au:N/C:P/I:P/A:P
Base Score:
5.1
Access Vector(AV) | Local (L) | Adjacent Network (A) | Network (N) |
---|---|---|---|
Access Complexity(AC) | High (H) | Medium (M) | Low (L) |
Authentication(Au) | Multiple (M) | Single (S) | None (N) |
Confidentiality Impact(C) | None (N) | Partial (P) | Complete (C) |
Integrity Impact(I) | None (N) | Partial (P) | Complete (C) |
Availability Impact(A) | None (N) | Partial (P) | Complete (C) |
Credit
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2016-1161 |
JVN iPedia |
|