ManageEngine ServiceDesk Plus Privilage Escalation Vulnerability
BID:72302
Info
ManageEngine ServiceDesk Plus Privilage Escalation Vulnerability
| Bugtraq ID: | 72302 |
| Class: | Design Error |
| CVE: |
CVE-2015-1480 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2015 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Muhammad Ahmed Siddiqui |
| Vulnerable: |
ManageEngine ServiceDesk Plus 9.0 |
| Not Vulnerable: |
ManageEngine ServiceDesk Plus 9.0 Build 9031 |
Discussion
ManageEngine ServiceDesk Plus Privilage Escalation Vulnerability
ManageEngine ServiceDesk Plus is prone to a privilege-escalation vulnerability.
An attacker can leverage this issue to gain elevated privileges and perform unauthorized actions which may aid in launching further attacks.
ManageEngine ServiceDesk Plus 9.0 is vulnerable; other versions may also be affected.
ManageEngine ServiceDesk Plus is prone to a privilege-escalation vulnerability.
An attacker can leverage this issue to gain elevated privileges and perform unauthorized actions which may aid in launching further attacks.
ManageEngine ServiceDesk Plus 9.0 is vulnerable; other versions may also be affected.
Exploit / POC
ManageEngine ServiceDesk Plus Privilage Escalation Vulnerability
Attackers can exploit this issue using standard tools.
Attackers can exploit this issue using standard tools.
Solution / Fix
ManageEngine ServiceDesk Plus Privilage Escalation Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
ManageEngine ServiceDesk Plus Privilage Escalation Vulnerability
References:
References:
- ServiceDesk Plus Homepage (ManageEngine)
- [REWTERZ-20140103] �?? Rewterz �?? Security Advisory (rewterz)