QID 378367
Date Published: 2023-04-17
QID 378367: Zoho ManageEngine ServiceDesk Plus and AssetExplorer Improper Access Control Vulnerability
Zoho ManageEngine ServiceDesk Plus and AssetExplorer are vulnerable to Improper Access Control vulnerability.
Using the approval login URL, which is used to approve purchase details without a login to the application, non-login users are able to extract vendor currency details.
Affected Versions:
ServiceDesk Plus 13000 and below
AssetExplorer 6970 and below
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine ServiceDesk Plus and AssetExplorer by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability may allow an users can extract all vendor currency details without logging in to the application.
Solution
Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory
Vendor References
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/service-desk/cve-2022-25245.html
CVEs related to QID 378367
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|