CVE-2022-25245: Medium severity zohocorp manageengine servicedesk plus vulnerability
Published Apr 5, 2022
·Updated
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
Affected Software
2 affected components
ZohoCorp ManageEngine ServiceDesk Plus<=12.0
ZohoCorp ManageEngine ServiceDesk Plus=13.0-13000
Remediation
Event History
Apr 5, 2022
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
Description
Frequently Asked Questions
1
What is CVE-2022-25245?
CVE-2022-25245 is a vulnerability in Zoho ManageEngine ServiceDesk Plus that allows anyone to know the organization's default currency name.
2
What is the severity of CVE-2022-25245?
The severity of CVE-2022-25245 is medium, with a severity score of 5.3.
3
Which versions of Zoho ManageEngine ServiceDesk Plus are affected by CVE-2022-25245?
Versions up to 12.0 and version 13.0-13000 of Zoho ManageEngine ServiceDesk Plus are affected by CVE-2022-25245.
4
How can I fix CVE-2022-25245?
You can fix CVE-2022-25245 by updating Zoho ManageEngine ServiceDesk Plus to a patched version provided by Zohocorp.
5
Where can I find more information about CVE-2022-25245?
You can find more information about CVE-2022-25245 on the official Zoho ManageEngine website and the Raxis blog.