ManageEngine Analytics Plus
cpe:2.3:a:zohocorp:manageengine_analytics_plus:*:*:*:*:*:*:*
- < 6130
A vulnerability exists in Zoho Analytics On-Premise and ManageEngine Analytics Plus versions prior to 6130, allowing for Active Directory (AD) account takeover. This issue arises from a hardcoded sensitive token, which could lead to unauthorized access to AD user accounts and exposure of user information. The vulnerability specifically affects Windows installations that use AD authentication without Single Sign-On (SSO) configuration.
Exploitation of this vulnerability could result in unauthorized access to AD user accounts, allowing for account takeovers and exposure of sensitive user information.
Users can upgrade to the latest version by downloading the upgrade pack from the ManageEngine or Zoho Analytics service pack pages and following the provided upgrade instructions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.