HIGH
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email
Published Jul 12, 2022
7.5
HIGHCVSS 3.1
EPSS 6.21%
Description
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
Affected products
No data.
Configuration 1
OR
- < 13.0
- 13.0
- 13.0
- 13.0
- 13.0
- 13.0
- 13.0
- 13.0
- 13.0
Configuration 2
OR
- < 10.6
- 10.6
- 10.6
- 10.6
- 10.6
- 10.6
- 10.6
Configuration 3
OR
- < 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
- 11.0
Configuration 4
OR
- < 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
- 6.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (1)
- https://www.manageengine.com/products/service-desk/cve-2022-35403.html x_refsource_MISCPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.manageengine.com/products/service-desk/cve-2022-35403.html | x_refsource_MISCPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 12, 2022
Updated Aug 3, 2024
Reserved Jul 8, 2022
Link CVE-2022-35403
CISA Vulnrichment
Updated n/a