PT-2019-13952 · Zoho · Zoho Manageengine Servicedesk Plus

CVE-2019-15045

·

Publicado

2019-08-21

·

Atualizado

2024-08-05

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ServiceDesk Plus version 10
Description The issue allows user enumeration through the AjaxDomainServlet. The vendor considers this as intended functionality.
Recommendations For Zoho ManageEngine ServiceDesk Plus version 10, consider restricting access to the AjaxDomainServlet to minimize the risk of user enumeration.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15045

Produtos afetados

Zoho Manageengine Servicedesk Plus