First published: Fri Jan 20 2023(Updated: )
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10600 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10601 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10602 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10603 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10604 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10605 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10606 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10607 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10608 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10609 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =10.6-10610 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =13.0-13000 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =13.0-13001 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =13.0-13002 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =13.0-13003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Zoho ManageEngine ServiceDesk Plus MSP is CVE-2023-22964.
The severity of CVE-2023-22964 is critical with a CVSS score of 9.1.
Zoho ManageEngine ServiceDesk Plus MSP versions before 10611 and 13x before 13004 are affected by CVE-2023-22964.
CVE-2023-22964 is an authentication bypass vulnerability in Zoho ManageEngine ServiceDesk Plus MSP when LDAP authentication is enabled.
To fix CVE-2023-22964, update Zoho ManageEngine ServiceDesk Plus MSP to version 10611 or 13004.