Site icon API Security Blog

ManageEngine Firewall Analyzer REST API Key Disclosure (CVE-2022-36923)

The ManageEngine Firewall Analyzer running on the remote host is affected by an information disclosure vulnerability. An unauthenticated, remote attacker can exploit this, via a specially crafted message, to obtain a user’s API key and then access the external APIs.Read More

Exit mobile version