CVE-2019-15045: Infoleak
Published Aug 21, 2019
·Updated
DISPUTED AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality.
Affected Software
1 affected component
ZohoCorp ManageEngine ServiceDesk Plus>=10<10509
Event History
Aug 21, 2019
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
Description
Disputed
07:15 PM
Frequently Asked Questions
1
What is CVE-2019-15045?
CVE-2019-15045 is a vulnerability in AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 that allows user enumeration.
2
What is the severity of CVE-2019-15045?
The severity of CVE-2019-15045 is medium, with a severity value of 5.3.
3
How does CVE-2019-15045 affect Zoho ManageEngine ServiceDesk Plus?
CVE-2019-15045 affects Zoho ManageEngine ServiceDesk Plus 10 by allowing user enumeration through the AjaxDomainServlet.
4
What is the vendor's position on CVE-2019-15045?
The vendor's position is that the user enumeration vulnerability in AjaxDomainServlet is intended functionality.
5
Can you provide more information about CVE-2019-15045?
CVE-2019-15045 is a vulnerability in Zoho ManageEngine ServiceDesk Plus 10 that allows an attacker to enumerate users.