CVE-2023-34197: Medium severity Zohocorp ManageEngine ServiceDesk Plus vulnerability
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoho ManageEngine ServiceDesk Plusto a version that resolves this vulnerability.Fixed in 14202 - Upgrade
Upgrade
Zoho ManageEngine ServiceDesk Plus MSPto a version that resolves this vulnerability.Fixed in 14300 - Upgrade
Upgrade
Zoho ManageEngine SupportCenter Plusto a version that resolves this vulnerability.Fixed in 14300
Event History
Frequently Asked Questions
What is CVE-2023-34197?
CVE-2023-34197 is a vulnerability in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus that allows unprivileged users to access and modify release tickets.
How severe is CVE-2023-34197?
CVE-2023-34197 has a severity rating of 5.4, which is considered medium.
Which versions of Zoho ManageEngine ServiceDesk Plus are affected by CVE-2023-34197?
CVE-2023-34197 affects Zoho ManageEngine ServiceDesk Plus versions up to and including 14.2.
How can unprivileged users exploit CVE-2023-34197?
Unprivileged users can exploit CVE-2023-34197 to access the Reminders of a release ticket and make modifications.
Is there a fix available for CVE-2023-34197?
Yes, a fix is available for CVE-2023-34197. It is recommended to update Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus to version 14.3 or higher.