Medium severity6.5NVD Advisory· Published Mar 2, 2022· Updated Jun 17, 2026
CVE-2022-24447
CVE-2022-24447
Description
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:zohocorp:manageengine_key_manager_plus:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:*:*:*:*:*:*:*:*range: <=5.9
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0:6000:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0:6001:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.0:6002:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6100:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6150:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6151:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6160:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_key_manager_plus:6.1:6161:*:*:*:*:*:*
- Zoho ManageEngine/Key Manager Plusdescription
- Range: <6200
- Range: <6200
Patches
Vulnerability mechanics
References
3- excellium-services.com/cert-xlm-advisory/cve-2022-24447/nvdThird Party Advisory
- www.manageengine.com/key-manager/release-notes.htmlnvdRelease NotesVendor Advisory
- cds.thalesgroup.com/en/tcs-cert/CVE-2022-24447nvd
News mentions
0No linked articles in our index yet.