CVE-2020-8509: High severity ZohoCorp Manageengine Desktop Central vulnerability
Published Mar 30, 2020
·Updated
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
Affected Software
1 affected component
ZohoCorp Manageengine Desktop Central<10.0.483
Event History
Mar 30, 2020
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-8509?
CVE-2020-8509 is a vulnerability in Zoho ManageEngine Desktop Central before 10.0.483 that allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
2
What is the severity of CVE-2020-8509?
The severity of CVE-2020-8509 is high, with a CVSS score of 7.5.
3
What is affected by CVE-2020-8509?
Zoho ManageEngine Desktop Central versions up to 10.0.483 are affected by CVE-2020-8509.
4
How can unauthenticated users exploit CVE-2020-8509?
Unauthenticated users can exploit CVE-2020-8509 by accessing the PDFGenerationServlet in Zoho ManageEngine Desktop Central before 10.0.483.
5
Are there any fixes or patches available for CVE-2020-8509?
To fix CVE-2020-8509, users should update Zoho ManageEngine Desktop Central to version 10.0.483 or higher.