VulnerabilityModified
CVE-2016-1159
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
MEDIUM 6.5EPSS 4.42%
Does this matter?
Lower severity and a low EPSS score (4.42%). Track it; it rarely justifies an emergency change on its own.
Description
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 4.42% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- zohocorp/manageengine password manager pro
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/vu/JVNVU90405898/index.htmlThird Party Advisory
- https://excellium-services.com/cert-xlm-advisory/cve-2016-1159/Third Party Advisory
- https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.htmlVendor Advisory
- https://www.manageengine.com/products/passwordmanagerpro/release-notes.htmlRelease Notes
- http://jvn.jp/vu/JVNVU90405898/index.htmlThird Party Advisory
- https://excellium-services.com/cert-xlm-advisory/cve-2016-1159/Third Party Advisory
- https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.htmlVendor Advisory
- https://www.manageengine.com/products/passwordmanagerpro/release-notes.htmlRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.