CVE-2017-11511: Infoleak
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-11511?
CVE-2017-11511 is a vulnerability in ManageEngine ServiceDesk 9.3.9328 that allows arbitrary file downloads.
How severe is CVE-2017-11511?
CVE-2017-11511 has a severity level of 7.5 (high).
How does CVE-2017-11511 affect ManageEngine ServiceDesk?
CVE-2017-11511 affects ManageEngine ServiceDesk 9.3.9328 and allows unauthenticated remote attackers to download arbitrary files.
Is there a fix for CVE-2017-11511?
To fix CVE-2017-11511, users should update to a version of ManageEngine ServiceDesk that is not affected by the vulnerability.
Where can I find more information about CVE-2017-11511?
You can find more information about CVE-2017-11511 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/101788) and [Tenable Research](https://www.tenable.com/security/research/tra-2017-31).