PT-2019-11677 · Manageengine · Manageengine Servicedesk Plus

Operat0R

·

Published

2019-04-04

·

Updated

2020-08-24

·

CVE-2019-10273

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ManageEngine ServiceDesk Plus version 9.3
Description The issue is related to information leakage in the "/mc login" API endpoint, allowing authenticated users to enumerate active users due to a flaw in authentication handling. This enables an attacker to login and verify any active account.
Recommendations For ManageEngine ServiceDesk Plus version 9.3, consider restricting access to the "/mc login" API endpoint until a patch is available. As a temporary workaround, limit the ability of authenticated users to enumerate active users by implementing additional authentication or authorization checks.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10273

Affected Products

Manageengine Servicedesk Plus