CVE-2024-52323: Sensitive Data Exposure

8.1 CVSS

Description

Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.

Classification

CVE ID: CVE-2024-52323

CVSS Base Severity: HIGH

CVSS Base Score: 8.1

Affected Products

Vendor: ManageEngine

Product: Analytics Plus

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.manageengine.com/analytics-plus/CVE-2024-52323.html

Timeline