PT-2019-13952 · Zoho · Zoho Manageengine Servicedesk Plus
CVE-2019-15045
·
Publicado
2019-08-21
·
Atualizado
2024-08-05
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ServiceDesk Plus version 10
Description
The issue allows user enumeration through the AjaxDomainServlet. The vendor considers this as intended functionality.
Recommendations
For Zoho ManageEngine ServiceDesk Plus version 10, consider restricting access to the AjaxDomainServlet to minimize the risk of user enumeration.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Zoho Manageengine Servicedesk Plus