
Cloud Vulnerability DB
A community-led vulnerabilities database
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, identified as CVE-2023-2291. The vulnerability affects multiple ManageEngine products including Access Manager Plus, Password Manager Pro, and PAM360. This security issue was discovered and disclosed to the vendor on January 23, 2023, with the public disclosure occurring on April 25, 2023 (Tenable Research).
The vulnerability involves hardcoded PostgreSQL credentials that allow access to the database server running under the SYSTEM account. The CVSSv3 Base Score is 8.8 (High) with a temporal score of 8.3, and a vector of AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The PostgreSQL database server used in AMP runs with SYSTEM privileges, though with limited administrative capabilities (Tenable Research).
The vulnerability allows a malicious actor with low-level privileges to modify configuration data and escalate their permissions to Administrative user level. Through the exploitation of these hardcoded credentials, an attacker can manipulate the AMP configuration files and execute arbitrary code under the security context of the AMP service (Tenable Research).
As of the initial disclosure, no vendor-supplied solution was available. Users are advised to contact ManageEngine support for mitigation assistance. The vendor acknowledged the vulnerability and indicated that patches were in development, though they were not ready for release at the time of disclosure (Tenable Research).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."