First published: Mon Mar 25 2019(Updated: )
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9362 is a vulnerability found in ManageEngine ServiceDesk Plus before version 9312 that allows an attacker to inject malicious XML code through the add Configuration items CMDB API.
CVE-2017-9362 has a severity score of 8.8 (high).
ManageEngine ServiceDesk Plus versions up to 9.3 are affected by CVE-2017-9362.
To fix CVE-2017-9362, upgrade ManageEngine ServiceDesk Plus to version 9312 or later.
You can find more information about CVE-2017-9362 at https://labs.integrity.pt/advisories/cve-2017-9362.