CVE-2017-9362: XEE
Published Mar 25, 2019
·Updated
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus<9.3
Event History
Mar 25, 2019
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
Description
Frequently Asked Questions
1
What is CVE-2017-9362?
CVE-2017-9362 is a vulnerability found in ManageEngine ServiceDesk Plus before version 9312 that allows an attacker to inject malicious XML code through the add Configuration items CMDB API.
2
How severe is CVE-2017-9362?
CVE-2017-9362 has a severity score of 8.8 (high).
3
What software is affected by CVE-2017-9362?
ManageEngine ServiceDesk Plus versions up to 9.3 are affected by CVE-2017-9362.
4
How can I fix CVE-2017-9362?
To fix CVE-2017-9362, upgrade ManageEngine ServiceDesk Plus to version 9312 or later.
5
Where can I find more information about CVE-2017-9362?
You can find more information about CVE-2017-9362 at https://labs.integrity.pt/advisories/cve-2017-9362.