CVE-2020-11946 — Missing Authentication for Critical Function in Manageengine Opmanager
Severity
7.5HIGHNVD
EPSS
67.0%
top 1.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 20
Latest updateMay 24
Description
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-67r2-78g2-6xw9: Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call↗2022-05-24
CVEList▶
CVE-2020-11946: Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call↗2020-04-20