First published: Sun Feb 17 2019(Updated: )
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <10.0 | |
<10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-8395 is critical with a CVSSv3 score of 9.8.
The affected software of CVE-2019-8395 is Zoho ManageEngine ServiceDesk Plus (SDP) version up to exclusive 10.0 build 10007.
CVE-2019-8395 is an Insecure Direct Object Reference (IDOR) vulnerability in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007, which allows an attacker to access attachments in a request.
To fix CVE-2019-8395, it is recommended to upgrade Zoho ManageEngine ServiceDesk Plus (SDP) to version 10.0 build 10007 or later.
You can find more information about CVE-2019-8395 on the Zoho ManageEngine ServiceDesk Plus (SDP) Readme page: https://www.manageengine.com/products/service-desk/readme.html