VYPR
Medium severity6.5NVD Advisory· Published Mar 2, 2022· Updated Jun 17, 2026

CVE-2022-24447

CVE-2022-24447

Description

An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:*:*:*:*:*:*:*:*range: <=5.9
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0:6000:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0:6001:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0:6002:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6100:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6150:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6151:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6160:*:*:*:*:*:*
    • cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6161:*:*:*:*:*:*
  • Zoho ManageEngine/Key Manager Plusdescription
  • Range: <6200
  • Range: <6200

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.