First published: Thu Sep 04 2014(Updated: )
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ManageEngine Device Expert | <=5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5377 is considered a medium severity vulnerability due to the potential exposure of user account credentials.
To fix CVE-2014-5377, upgrade to ManageEngine DeviceExpert version 5.9 build 5981 or later.
CVE-2014-5377 is a credential disclosure vulnerability that allows attackers to obtain user account credentials.
ManageEngine DeviceExpert versions prior to 5.9 build 5981 are affected by CVE-2014-5377.
Yes, CVE-2014-5377 can be exploited remotely by attackers who send direct requests.