An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).
The product makes files or directories accessible to unauthorized actors, even though they should not be.
Link | Tags |
---|---|
https://www.manageengine.com/data-security/release-notes.html | release notes vendor advisory |
https://excellium-services.com/cert-xlm-advisory/cve-2019-17112/ | third party advisory |