PT-2011-4066 · Manageengine · Manageengine Servicedesk Plus

Keith Lee Yong Ming

·

Published

2011-07-17

·

Updated

2011-07-19

·

CVE-2011-2756

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine ServiceDesk Plus version 8.0 before Build 8012
Description The issue concerns a lack of authentication requirement in the FileDownload.jsp component, allowing remote attackers to read files from a specific directory.
Recommendations For ManageEngine ServiceDesk Plus version 8.0 before Build 8012, update to Build 8012 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2756

Affected Products

Manageengine Servicedesk Plus