4.9

CVE-2023-29443

Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZohocorpManageengine Assetexplorer Version6.9 Update6980
ZohocorpManageengine Assetexplorer Version6.9 Update6981
ZohocorpManageengine Assetexplorer Version6.9 Update6982
ZohocorpManageengine Assetexplorer Version6.9 Update6983
ZohocorpManageengine Assetexplorer Version6.9 Update6984
ZohocorpManageengine Assetexplorer Version6.9 Update6985
ZohocorpManageengine Assetexplorer Version6.9 Update6986
ZohocorpManageengine Assetexplorer Version6.9 Update6987
ZohocorpManageengine Assetexplorer Version6.9 Update6988
ZohocorpManageengine Servicedesk Plus Version14.1 Update-
ZohocorpManageengine Servicedesk Plus Version14.1 Update14100
ZohocorpManageengine Servicedesk Plus Version14.1 Update14101
ZohocorpManageengine Servicedesk Plus Version14.1 Update14102
ZohocorpManageengine Servicedesk Plus Version14.1 Update14103
ZohocorpManageengine Servicedesk Plus Version14.1 Update14104
ZohocorpManageengine Servicedesk Plus Msp Version14.0 Update14000
ZohocorpManageengine Servicedesk Plus Msp Version14.0 Update14001
ZohocorpManageengine Supportcenter Plus Version14.0 Update14000
ZohocorpManageengine Supportcenter Plus Version14.0 Update14001
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.649
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.