ZVE-2020-1820

Unauthenticated access to API key disclosure from a servlet call

 

Vulnerability Details
ImpactHigh
Reported on29 Jun 2018
Reported byInternal, filed on Zoho Bug Bounty
Fixed on29 Nov 2018
Affected BuildsTill Build 123147
Fixed inBuild 125120
OverviewUnauthenticated access to API key disclosure from a servlet call
Recommended FixUpgrade to Firewall Analyzer Version 12.5.120 or above.

 

Description

Unauthenticated access to API key disclosure from a servlet call

We recommend that you upgrade to Firewall Analyzer version 12.5.120 and above to fix this issue.

Source and Acknowledgements

Find out more about ZVE-2020-1820 from the ZVE dictionary.

Need Help?

For clarification or corrections please contact our support team or email us at fwanalyzer-support@manageengine.com

A single platter for comprehensive Network Security Device Management