6.5

CVE-2019-8394

Warnung
Exploit
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update -
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10000
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10001
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10002
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10003
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10004
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10005
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10006
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10007
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10008
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10009
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10010
Zohocorp ≫ Manageengine Servicedesk Plus Version 10.0.0 Update 10011

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

Schwachstelle

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 63.34% 0.991
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://www.manageengine.com/products/service-desk/readme.html
Vendor Advisory
Release Notes
http://www.securityfocus.com/bid/107129
Third Party Advisory
VDB Entry
https://www.exploit-db.com/exploits/46413/
Third Party Advisory
Exploit
VDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-8394
US Government Resource