ZDI-23-230: ManageEngine ServiceDesk Plus ImageUploadServlet Improper Input Validation Denial-of-Service Vulnerability
Published Mar 9, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ManageEngine ServiceDesk Plus. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
ManageEngine ServiceDesk Plus
Event History
Mar 9, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-230?
ZDI-23-230 is classified as a denial-of-service vulnerability.
2
How do I fix ZDI-23-230?
To fix ZDI-23-230, ensure you have the latest patches or updates provided by ManageEngine for ServiceDesk Plus.
3
Who can exploit ZDI-23-230?
ZDI-23-230 can be exploited by remote attackers with authentication access to the affected installations.
4
What type of vulnerability is ZDI-23-230?
ZDI-23-230 is a denial-of-service vulnerability that affects ManageEngine ServiceDesk Plus.
5
What is the impact of ZDI-23-230?
The impact of ZDI-23-230 is the potential to disrupt service availability on affected installations of ManageEngine ServiceDesk Plus.