Vulnerabilities > CVE-2019-17112 - Files or Directories Accessible to External Parties vulnerability in Zohocorp Manageengine Datasecurity Plus
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 24 |