ZDI-CAN-19536: ZDI-23-229: ManageEngine ServiceDesk Plus MSP generateSQLReport Improper Input Validation Privilege Escalation Vulnerability
Published Mar 9, 2023
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of ManageEngine ServiceDesk Plus MSP. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
ManageEngine ServiceDesk Plus MSP
Event History
Mar 9, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19536?
The severity of ZDI-CAN-19536 is critical due to its potential for remote privilege escalation.
2
How do I fix ZDI-CAN-19536?
To fix ZDI-CAN-19536, apply the latest security updates provided by ManageEngine for ServiceDesk Plus MSP.
3
Who is affected by ZDI-CAN-19536?
ZDI-CAN-19536 affects installations of ManageEngine ServiceDesk Plus MSP that have authentication enabled.
4
What types of attacks are possible with ZDI-CAN-19536?
ZDI-CAN-19536 allows remote attackers to escalate privileges on vulnerable systems after authentication.
5
Is authentication required to exploit ZDI-CAN-19536?
Yes, authentication is required to exploit the ZDI-CAN-19536 vulnerability.