PT-2008-2107 · Zoho · Zoho Manageengine Applications Manager
Published
2008-01-29
·
Updated
2017-08-08
·
CVE-2008-0475
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ManageEngine Applications Manager version 8.1 build 8100
Description
The issue allows remote attackers to obtain sensitive information via an invalid URI. For example, using the "/-" URI, an attacker can access sensitive data, such as that found in the "Home->Summary" section.
Recommendations
For ManageEngine Applications Manager version 8.1 build 8100, consider restricting access to the sensitive information section, such as "Home->Summary", until a fix is available. As a temporary workaround, avoid using invalid URIs, such as "/-", to prevent potential exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Applications Manager