Medium severity4.3NVD Advisory· Published Mar 1, 2022· Updated Jun 17, 2026
CVE-2022-24446
CVE-2022-24446
Description
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6100:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6150:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6151:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6160:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1.6:build6161:*:*:*:*:*:*
- Zoho ManageEngine/Key Manager Plusdescription
- Range: <6.2.00
Patches
Vulnerability mechanics
References
3- excellium-services.com/cert-xlm-advisory/cve-2022-24446/nvdThird Party Advisory
- www.manageengine.com/key-manager/release-notes.htmlnvdRelease NotesVendor Advisory
- cds.thalesgroup.com/en/tcs-cert/CVE-2022-24446nvd
News mentions
0No linked articles in our index yet.