CVE-2019-17112: Zohocorp ManageEngine Datasecurity Plus

Medium severity, CVSS 4.3. EPSS: 2.1% chance of exploitation in the next 30 days.

An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).

Affected products

  • Zohocorp ManageEngine Datasecurity Plus: version 4.0 only; version 4.1 only; version 4.2 only; version 4.3 only; version 5.0 only

Published 2019-10-09. Last modified 2026-06-17.