CVE-2011-2756: Medium severity manageengine servicedesk plus vulnerability
Published Jul 17, 2011
·Updated
FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.
Affected Software
1 affected component
ManageEngine ServiceDesk Plus=8.0
Event History
Jul 17, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2756?
CVE-2011-2756 is considered a high severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2011-2756?
To mitigate CVE-2011-2756, upgrade to ManageEngine ServiceDesk Plus version 8.0 Build 8012 or later.
3
What type of vulnerability is CVE-2011-2756?
CVE-2011-2756 is an authentication bypass vulnerability that allows unauthorized file access.
4
What versions of ManageEngine ServiceDesk Plus are affected by CVE-2011-2756?
CVE-2011-2756 affects ManageEngine ServiceDesk Plus version 8.0 prior to Build 8012.
5
Can CVE-2011-2756 be exploited remotely?
Yes, CVE-2011-2756 can be exploited remotely by attackers to access files without authentication.