5.4

CVE-2023-34197

Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Servicedesk Plus Version14.2 Update14200
ZohocorpManageengine Servicedesk Plus Version14.2 Update14201
ZohocorpManageengine Servicedesk Plus Msp Version14.2 Update14200
ZohocorpManageengine Servicedesk Plus Msp Version14.2 Update14201
ZohocorpManageengine Servicedesk Plus Msp Version14.2 Update14202
ZohocorpManageengine Supportcenter Plus Version14.2 Update14200
ZohocorpManageengine Supportcenter Plus Version14.2 Update14201
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.282
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.