First published: Fri Jul 07 2023(Updated: )
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Servicedesk Plus | <14.2 | |
Zohocorp Manageengine Servicedesk Plus | =14.2-14200 | |
Zohocorp Manageengine Servicedesk Plus | =14.2-14201 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | <14.2 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =14.2-14200 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =14.2-14201 | |
Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | =14.2-14202 | |
Zohocorp Manageengine Supportcenter Plus | <14.2 | |
Zohocorp Manageengine Supportcenter Plus | =14.2-14200 | |
Zohocorp Manageengine Supportcenter Plus | =14.2-14201 | |
Zohocorp Manageengine Servicedesk Plus Msp | <14.2 | |
Zohocorp Manageengine Servicedesk Plus Msp | =14.2-14200 | |
Zohocorp Manageengine Servicedesk Plus Msp | =14.2-14201 | |
Zohocorp Manageengine Servicedesk Plus Msp | =14.2-14202 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34197 is a vulnerability in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus that allows unprivileged users to access and modify release tickets.
CVE-2023-34197 has a severity rating of 5.4, which is considered medium.
CVE-2023-34197 affects Zoho ManageEngine ServiceDesk Plus versions up to and including 14.2.
Unprivileged users can exploit CVE-2023-34197 to access the Reminders of a release ticket and make modifications.
Yes, a fix is available for CVE-2023-34197. It is recommended to update Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus to version 14.3 or higher.