PT-2020-20186 · Zoho · Zoho Manageengine Desktop Central
Kalimer0X00
·
Published
2020-03-30
·
Updated
2022-04-06
·
CVE-2020-8509
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Desktop Central versions prior to 10.0.483
Description
The issue allows unauthenticated users to access the
PDFGenerationServlet, leading to sensitive information disclosure.Recommendations
For versions prior to 10.0.483, update to version 10.0.483 or later to resolve the issue. As a temporary workaround, consider restricting access to the
PDFGenerationServlet to minimize the risk of exploitation.Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoho Manageengine Desktop Central