PT-2019-11677 · Manageengine · Manageengine Servicedesk Plus
Operat0R
·
Published
2019-04-04
·
Updated
2020-08-24
·
CVE-2019-10273
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ManageEngine ServiceDesk Plus version 9.3
Description
The issue is related to information leakage in the "/mc login" API endpoint, allowing authenticated users to enumerate active users due to a flaw in authentication handling. This enables an attacker to login and verify any active account.
Recommendations
For ManageEngine ServiceDesk Plus version 9.3, consider restricting access to the "/mc login" API endpoint until a patch is available. As a temporary workaround, limit the ability of authenticated users to enumerate active users by implementing additional authentication or authorization checks.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Manageengine Servicedesk Plus