Vulnerability Description
An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Applications Manager | 12.3 |
Related Weaknesses (CWE)
References
- http://applications.comProduct
- http://manageengine.comVendor Advisory
- https://www.manageengine.com/Vendor Advisory
- https://www.trustwave.com/en-us/resources/security-resources/security-advisoriesBroken LinkExploitThird Party Advisory
- http://applications.comProduct
- http://manageengine.comVendor Advisory
- https://www.manageengine.com/Vendor Advisory
- https://www.trustwave.com/en-us/resources/security-resources/security-advisoriesBroken LinkExploitThird Party Advisory
FAQ
What is CVE-2017-11557?
CVE-2017-11557 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environmen...
How severe is CVE-2017-11557?
CVE-2017-11557 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11557?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Applications Manager.