First published: Wed Aug 21 2019(Updated: )
** DISPUTED ** AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | >=10<10509 | |
>=10<10509 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15045 is a vulnerability in AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 that allows user enumeration.
The severity of CVE-2019-15045 is medium, with a severity value of 5.3.
CVE-2019-15045 affects Zoho ManageEngine ServiceDesk Plus 10 by allowing user enumeration through the AjaxDomainServlet.
The vendor's position is that the user enumeration vulnerability in AjaxDomainServlet is intended functionality.
CVE-2019-15045 is a vulnerability in Zoho ManageEngine ServiceDesk Plus 10 that allows an attacker to enumerate users.