2017-10-16 12:31:07 -04:00
{
2019-03-18 06:10:47 +00:00
"CVE_data_meta" : {
2020-03-09 17:01:16 +00:00
"ASSIGNER" : "vultures@jpcert.or.jp" ,
2019-03-18 06:10:47 +00:00
"ID" : "CVE-2016-1159" ,
2020-03-09 17:01:16 +00:00
"STATE" : "PUBLIC"
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "ZOHO" ,
"product" : {
"product_data" : [
{
"product_name" : "Password Manager Pro (PMP)" ,
"version" : {
"version_data" : [
{
"version_value" : "8.3.0 (Build 8303"
} ,
{
"version_value" : "8.4.0 (Build 8400"
} ,
{
"version_value" : "8401"
} ,
{
"version_value" : "8402)."
}
]
}
}
]
}
}
]
}
2019-03-18 06:10:47 +00:00
} ,
"data_format" : "MITRE" ,
"data_type" : "CVE" ,
"data_version" : "4.0" ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2020-03-09 17:01:16 +00:00
"value" : "In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service."
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "obtain sensitive information"
}
]
}
]
} ,
"references" : {
"reference_data" : [
{
"url" : "https://excellium-services.com/cert-xlm-advisory/cve-2016-1159/" ,
"refsource" : "MISC" ,
"name" : "https://excellium-services.com/cert-xlm-advisory/cve-2016-1159/"
} ,
{
"url" : "https://www.manageengine.com/products/passwordmanagerpro/release-notes.html" ,
"refsource" : "MISC" ,
"name" : "https://www.manageengine.com/products/passwordmanagerpro/release-notes.html"
} ,
{
"url" : "http://jvn.jp/vu/JVNVU90405898/index.html" ,
"refsource" : "MISC" ,
"name" : "http://jvn.jp/vu/JVNVU90405898/index.html"
} ,
{
"refsource" : "CONFIRM" ,
"name" : "https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.html" ,
"url" : "https://www.manageengine.com/products/passwordmanagerpro/issues-fixed.html"
2019-03-18 06:10:47 +00:00
}
]
}
}