First published: Mon Mar 30 2020(Updated: )
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Desktop Central | <10.0.483 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8509 is a vulnerability in Zoho ManageEngine Desktop Central before 10.0.483 that allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
The severity of CVE-2020-8509 is high, with a CVSS score of 7.5.
Zoho ManageEngine Desktop Central versions up to 10.0.483 are affected by CVE-2020-8509.
Unauthenticated users can exploit CVE-2020-8509 by accessing the PDFGenerationServlet in Zoho ManageEngine Desktop Central before 10.0.483.
To fix CVE-2020-8509, users should update Zoho ManageEngine Desktop Central to version 10.0.483 or higher.