Zoho ManageEngine ServiceDesk Plus CVE-2017-9362 XML External Entity Injection Vulnerability
BID:107569
Info
Zoho ManageEngine ServiceDesk Plus CVE-2017-9362 XML External Entity Injection Vulnerability
| Bugtraq ID: | 107569 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-9362 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2017 12:00AM |
| Updated: | Sep 19 2017 12:00AM |
| Credit: | Paulo Monteiro and Filipe Reis |
| Vulnerable: |
Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9311 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9310 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9309 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9308 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9307 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9306 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9305 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9304 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9303 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9302 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9301 Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9300 |
| Not Vulnerable: |
Zohocorp ManageEngine ServiceDesk Plus 9.3 Build 9312 |
Exploit / POC
Zoho ManageEngine ServiceDesk Plus CVE-2017-9362 XML External Entity Injection Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Zoho ManageEngine ServiceDesk Plus CVE-2017-9362 XML External Entity Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.