QID 378355

Date Published: 2023-04-17

QID 378355: Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus and AssetExplorer Extensible Markup Language (XML) External Entity (XXE) Vulnerability

Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus and AssetExplorer are vulnerable to XXE vulnerability when integrating with Analytics Plus.

Threat actors with admin role access can retrieve local files from the server running the affected products.

Affected Versions:
ServiceDesk Plus versions 14000 and below
ServiceDesk Plus MSP versions 13000 and below
SupportCenter Plus versions 11025 and below
AssetExplorer version 6980

QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus and AssetExplorer by reading the version from buildinfo.xml file.

Successful exploitation of this vulnerability may allow threat actors with admin role access can retrieve local files from the server running the affected products.

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory

    Vendor References

    CVEs related to QID 378355

    Software Advisories
    Advisory ID Software Component Link
    Zoho ManageEngine Security Advisory URL Logo www.manageengine.com/products/service-desk/CVE-2022-40771.html