CVE-2011-1509: Medium severity manageengine servicedesk plus vulnerability
The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1509?
CVE-2011-1509 is considered a medium severity vulnerability due to the risk of password exposure.
How do I fix CVE-2011-1509?
To fix CVE-2011-1509, upgrade to a version of ManageEngine ServiceDesk Plus that is later than 8012.
What can attackers do with CVE-2011-1509?
Attackers can potentially intercept and decrypt passwords stored in cookies due to the weak encryption method used.
Is CVE-2011-1509 specific to certain versions of ManageEngine ServiceDesk Plus?
Yes, CVE-2011-1509 specifically affects ManageEngine ServiceDesk Plus versions 8012 and earlier.
What type of encryption is flawed in CVE-2011-1509?
CVE-2011-1509 uses a Caesar cipher for encryption, which is not secure for protecting sensitive information.