CVE-2016-4889: High severity zoho manageengine servicedesk plus vulnerability
Published Apr 14, 2017
·Updated
ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
Affected Software
1 affected component
ZohoCorp Servicedesk Plus<=8.2
Event History
Apr 14, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4889?
CVE-2016-4889 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2016-4889?
To fix CVE-2016-4889, upgrade to ServiceDesk Plus version 9.0 or later.
3
Who is affected by CVE-2016-4889?
CVE-2016-4889 affects users of ZOHO ManageEngine ServiceDesk Plus prior to version 9.0.
4
What type of vulnerability is CVE-2016-4889?
CVE-2016-4889 is an access control vulnerability that allows unauthorized functions to be accessed.
5
Can CVE-2016-4889 be exploited by unauthenticated users?
No, CVE-2016-4889 requires remote authenticated guest users for exploitation.