ZDI-CAN-19537: ZDI-23-230: ManageEngine ServiceDesk Plus ImageUploadServlet Improper Input Validation Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ManageEngine ServiceDesk Plus. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19537?
The severity of ZDI-CAN-19537 is classified as high due to its ability to create a denial-of-service condition.
How does ZDI-CAN-19537 affect ManageEngine ServiceDesk Plus?
ZDI-CAN-19537 allows remote attackers with authentication to disrupt service on affected installations of ManageEngine ServiceDesk Plus.
Is authentication required to exploit ZDI-CAN-19537?
Yes, authentication is required to exploit the ZDI-CAN-19537 vulnerability.
What are the potential consequences of ZDI-CAN-19537?
The potential consequences of ZDI-CAN-19537 include a denial-of-service condition, leading to service unavailability.
How can I mitigate ZDI-CAN-19537?
Mitigation strategies for ZDI-CAN-19537 include applying the latest security patches and monitoring logs for unusual authentication attempts.