CVE-2020-11946Missing Authentication for Critical Function in Manageengine Opmanager

Severity
7.5HIGHNVD
EPSS
67.0%
top 1.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 20
Latest updateMay 24

Description

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-67r2-78g2-6xw9: Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call2022-05-24
CVEList
CVE-2020-11946: Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call2020-04-20
CVE-2020-11946 — Manageengine Opmanager vulnerability | cvebase