PT-2022-21363 · Zoho · Manageengine Servicedesk Plus
Poh Jia Hao
·
Published
2022-07-01
·
Updated
2022-07-12
·
CVE-2022-32551
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ServiceDesk Plus MSP versions prior to 10604
Description
The issue allows path traversal, specifically to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml.
Recommendations
For versions prior to 10604, update to version 10604 or later to resolve the issue. As a temporary workaround, consider restricting access to the sample/WEB-INF/web.xml and sample/META-INF/web.xml files to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Manageengine Servicedesk Plus