CVE-2019-8395: Path Traversal
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-8395?
The severity of CVE-2019-8395 is critical with a CVSSv3 score of 9.8.
What is the affected software of CVE-2019-8395?
The affected software of CVE-2019-8395 is Zoho ManageEngine ServiceDesk Plus (SDP) version up to exclusive 10.0 build 10007.
What is the description of CVE-2019-8395?
CVE-2019-8395 is an Insecure Direct Object Reference (IDOR) vulnerability in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007, which allows an attacker to access attachments in a request.
How can I fix CVE-2019-8395?
To fix CVE-2019-8395, it is recommended to upgrade Zoho ManageEngine ServiceDesk Plus (SDP) to version 10.0 build 10007 or later.
Where can I find more information about CVE-2019-8395?
You can find more information about CVE-2019-8395 on the Zoho ManageEngine ServiceDesk Plus (SDP) Readme page: https://www.manageengine.com/products/service-desk/readme.html