Published:2016/05/16 Last Updated:2016/05/16
JVNVU#90405898
ManageEngine Password Manager Pro fails to restrict access permissions
Overview
ManageEngine Password Manager Pro fails to restrict access permissions.
Products Affected
- Password Manager Pro 8.3.0 (Build 8303)
- Password Manager Pro 8.4.0 (Build 8400, 8401, 8402)
Description
ManageEngine Password Manager Pro provided by Zoho Corporation fails to restrict access permissions.
Impact
A user may gain unauthorized access to other users' password entry history.
Solution
Update the Software
This vulnerability has been addressed in Password Manager Pro 8.4.0 (Build 8403).
Update to the latest version according to the information provided by the developer.
Vendor Status
Vendor | Link |
Zoho Corporation | ManageEngine Password Manager Pro - Issues Fixed |
ManageEngine Password Manager Pro - Release Notes |
References
-
Excellium Services
CVE-2016-1159 -
JPCERT/CC Official Blog May 06, 2016
Some coordinated vulnerability disclosures in April 2016
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score:
6.5
Attack Vector(AV) | Physical (P) | Local (L) | Adjacent (A) | Network (N) |
---|---|---|---|---|
Attack Complexity(AC) | High (H) | Low (L) | ||
Privileges Required(PR) | High (H) | Low (L) | None (N) | |
User Interaction(UI) | Required (R) | None (N) | ||
Scope(S) | Unchanged (U) | Changed (C) | ||
Confidentiality Impact(C) | None (N) | Low (L) | High (H) | |
Integrity Impact(I) | None (N) | Low (L) | High (H) | |
Availability Impact(A) | None (N) | Low (L) | High (H) |
CVSS v2
AV:N/AC:L/Au:S/C:C/I:N/A:N
Base Score:
6.8
Access Vector(AV) | Local (L) | Adjacent Network (A) | Network (N) |
---|---|---|---|
Access Complexity(AC) | High (H) | Medium (M) | Low (L) |
Authentication(Au) | Multiple (M) | Single (S) | None (N) |
Confidentiality Impact(C) | None (N) | Partial (P) | Complete (C) |
Integrity Impact(I) | None (N) | Partial (P) | Complete (C) |
Availability Impact(A) | None (N) | Partial (P) | Complete (C) |
Credit
Other Information
JPCERT Alert |
|
JPCERT Reports |
|
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2016-1159 |
JVN iPedia |
|