First published: Fri Apr 14 2017(Updated: )
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
zohocorp ServiceDesk plus | <=9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4890 is considered a medium severity vulnerability due to its potential to expose sensitive password information.
To fix CVE-2016-4890, upgrade ZOHO ManageEngine ServiceDesk Plus to version 9.2 or later.
CVE-2016-4890 allows attackers to exploit insecure cookie generation, potentially leading to unauthorized access to sensitive information.
CVE-2016-4890 affects ZOHO ManageEngine ServiceDesk Plus versions prior to 9.2.
Consider using other service desk software solutions that prioritize secure cookie handling to avoid vulnerabilities like CVE-2016-4890.