An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Microsoft Subscribe
Windows Subscribe
Zohocorp Subscribe
Manageengine Access Manager Plus Subscribe
Manageengine Adaudit Plus Subscribe
Manageengine Admanager Plus Subscribe
Manageengine Adselfservice Plus Subscribe
Manageengine Analytics Plus Subscribe
Manageengine Appcreator Subscribe
Manageengine Application Control Plus Subscribe
Manageengine Assetexplorer Subscribe
Manageengine Browser Security Plus Subscribe
Manageengine Cloud Security Plus Subscribe
Manageengine Datasecurity Plus Subscribe
Manageengine Device Control Plus Subscribe
Manageengine Endpoint Central Subscribe
Manageengine Endpoint Central Msp Subscribe
Manageengine Endpoint Dlp Plus Subscribe
Manageengine Exchange Reporter Plus Subscribe
Manageengine Firewall Analyzer Subscribe
Manageengine Log360 Ueba Subscribe
Manageengine M365 Manager Plus Subscribe
Manageengine M365 Security Plus Subscribe
Manageengine Mobile Device Manager Plus Subscribe
Manageengine Netflow Analyzer Subscribe
Manageengine Network Configuration Manager Subscribe
Manageengine Opmanager Subscribe
Manageengine Oputils Subscribe
Manageengine Os Deployer Subscribe
Manageengine Pam360 Subscribe
Manageengine Password Manager Pro Subscribe
Manageengine Patch Connect Plus Subscribe
Manageengine Patch Manager Plus Subscribe
Manageengine Recoverymanager Plus Subscribe
Manageengine Remote Access Plus Subscribe
Manageengine Remote Monitoring And Management Subscribe
Manageengine Secure Gateway Server Subscribe
Manageengine Servicedesk Plus Subscribe
Manageengine Servicedesk Plus Msp Subscribe
Manageengine Sharepoint Manager Plus Subscribe
Manageengine Supportcenter Plus Subscribe
Manageengine Vulnerability Manager Plus Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-58361 An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00064}

epss

{'score': 0.00084}


Thu, 13 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
Description An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database. An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2025-02-13T17:26:03.759Z

Reserved: 2023-11-13T15:10:28.339Z

Link: CVE-2023-6105

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-15T21:15:08.490

Modified: 2025-02-13T18:16:03.270

Link: CVE-2023-6105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses