VulnerabilityModified
CVE-2017-11557
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3.
MEDIUM 5.3EPSS 3.70%
Does this matter?
Lower severity and a low EPSS score (3.70%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 3.70% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- zohocorp/manageengine applications manager
- Source
- cve@mitre.org
References
- http://applications.comProduct
- http://manageengine.comVendor Advisory
- https://www.manageengine.com/Vendor Advisory
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18738Broken Link, Exploit, Third Party Advisory
- http://applications.comProduct
- http://manageengine.comVendor Advisory
- https://www.manageengine.com/Vendor Advisory
- https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=18738Broken Link, Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.