CWE
611
Advisory Published
Updated

CVE-2023-29443: XEE

First published: Wed Apr 26 2023(Updated: )

Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Zohocorp Manageengine Assetexplorer=6.9-6980
Zohocorp Manageengine Assetexplorer=6.9-6981
Zohocorp Manageengine Assetexplorer=6.9-6982
Zohocorp Manageengine Assetexplorer=6.9-6983
Zohocorp Manageengine Assetexplorer=6.9-6984
Zohocorp Manageengine Assetexplorer=6.9-6985
Zohocorp Manageengine Assetexplorer=6.9-6986
Zohocorp Manageengine Assetexplorer=6.9-6987
Zohocorp Manageengine Assetexplorer=6.9-6988
Zohocorp Manageengine Servicedesk Plus<14.1
Zohocorp Manageengine Servicedesk Plus=14.1
Zohocorp Manageengine Servicedesk Plus=14.1-14100
Zohocorp Manageengine Servicedesk Plus=14.1-14101
Zohocorp Manageengine Servicedesk Plus=14.1-14102
Zohocorp Manageengine Servicedesk Plus=14.1-14103
Zohocorp Manageengine Servicedesk Plus=14.1-14104
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus<14.0
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus=14.0-14000
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus=14.0-14001
Zohocorp Manageengine Supportcenter Plus<14.0
Zohocorp Manageengine Supportcenter Plus=14.0-14000
Zohocorp Manageengine Supportcenter Plus=14.0-14001

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2023-29443?

    CVE-2023-29443 is a vulnerability in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, SupportCenter Plus, and AssetExplorer that allows SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

  • What software versions are affected by CVE-2023-29443?

    Versions of Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 are affected by CVE-2023-29443.

  • How severe is CVE-2023-29443?

    CVE-2023-29443 has a severity level of 4.9 out of 10, which is considered medium.

  • What is the Common Weakness Enumeration (CWE) for CVE-2023-29443?

    The CWE for CVE-2023-29443 is CWE-611.

  • Is there a fix for CVE-2023-29443?

    Yes, upgrading to versions 14105 for Zoho ManageEngine ServiceDesk Plus, 14200 for ServiceDesk Plus MSP and SupportCenter Plus, and 6989 for AssetExplorer will fix the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203