5
CVE-2011-1509
- EPSS 0.79%
- Veröffentlicht 20.09.2011 10:55:02
- Zuletzt bearbeitet 16.06.2026 23:29:31
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Manageengine ≫ Servicedesk Plus Version <= 8012
Manageengine ≫ Servicedesk Plus Version8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.79% | 0.513 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://securityreason.com/securityalert/8385
http://www.coresecurity.com/content/multiples-vulnerabilities-manageengine-sdp
http://www.securityfocus.com/archive/1/519652/100/0/threaded
http://www.securityfocus.com/bid/49636
https://exchange.xforce.ibmcloud.com/vulnerabilities/69841