PT-2022-21363 · Zoho · Manageengine Servicedesk Plus

Poh Jia Hao

·

Published

2022-07-01

·

Updated

2022-07-12

·

CVE-2022-32551

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10604
Description The issue allows path traversal, specifically to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml.
Recommendations For versions prior to 10604, update to version 10604 or later to resolve the issue. As a temporary workaround, consider restricting access to the sample/WEB-INF/web.xml and sample/META-INF/web.xml files to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32551

Affected Products

Manageengine Servicedesk Plus