CVE-2016-1159

In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zohocorp:manageengine_password_manager_pro:8.3:build8303:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:8.4:build8400:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:8.4:build8401:*:*:*:*:*:*
cpe:2.3:a:zohocorp:manageengine_password_manager_pro:8.4:build8402:*:*:*:*:*:*

History

21 Nov 2024, 02:45

Type Values Removed Values Added
References () http://jvn.jp/vu/JVNVU90405898/index.html - Third Party Advisory () http://jvn.jp/vu/JVNVU90405898/index.html - Third Party Advisory
References () https://excellium-services.com/cert-xlm-advisory/cve-2016-1159/ - Third Party Advisory () https://excellium-services.com/cert-xlm-advisory/cve-2016-1159/ - Third Party Advisory
References () https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.html - Vendor Advisory () https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.html - Vendor Advisory
References () https://www.manageengine.com/products/passwordmanagerpro/release-notes.html - Release Notes () https://www.manageengine.com/products/passwordmanagerpro/release-notes.html - Release Notes

Information

Published : 2020-03-09 17:15

Updated : 2024-11-21 02:45


NVD link : CVE-2016-1159

Mitre link : CVE-2016-1159

CVE.ORG link : CVE-2016-1159


JSON object : View

Products Affected

zohocorp

  • manageengine_password_manager_pro
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor