Zoho ManageEngine ServiceDesk Plus CVE-2019-12252 Access Bypass Vulnerability
BID:108456
CVE-2019-12252 |Info
Zoho ManageEngine ServiceDesk Plus CVE-2019-12252 Access Bypass Vulnerability
| Bugtraq ID: | 108456 |
| Class: | Access Validation Error |
| CVE: |
CVE-2019-12252 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2019 12:00AM |
| Updated: | May 22 2019 12:00AM |
| Credit: | Enter of VinCSS (Vingroup) |
| Vulnerable: |
Zohocorp ManageEngine ServiceDesk Plus 9.4 Zohocorp ManageEngine ServiceDesk Plus 9.3 Zohocorp ManageEngine ServiceDesk Plus 9.2 Zohocorp ManageEngine ServiceDesk Plus 9.1 Zohocorp ManageEngine ServiceDesk Plus 9.0 Zohocorp ManageEngine ServiceDesk Plus 8.2 Zohocorp ManageEngine ServiceDesk Plus 10.5 Zohocorp ManageEngine ServiceDesk Plus 10 |
| Not Vulnerable: | |
Discussion
Zoho ManageEngine ServiceDesk Plus CVE-2019-12252 Access Bypass Vulnerability
Zoho ManageEngine ServiceDesk Plus is prone to an access-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Zoho ManageEngine ServiceDesk Plus through 10.5 are vulnerable.
Zoho ManageEngine ServiceDesk Plus is prone to an access-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Zoho ManageEngine ServiceDesk Plus through 10.5 are vulnerable.
Solution / Fix
Zoho ManageEngine ServiceDesk Plus CVE-2019-12252 Access Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Zoho ManageEngine ServiceDesk Plus CVE-2019-12252 Access Bypass Vulnerability
References:
References: