CVE-2016-1159: Zohocorp ManageEngine Password Manager Pro

Medium severity, CVSS 6.5. EPSS: 4.4% chance of exploitation in the next 30 days.

In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.

Affected products

  • Zohocorp ManageEngine Password Manager Pro: version 8.3 only; version 8.4 only

Published 2020-03-09. Last modified 2026-06-17.