CVE-2020-13154
18.05.2020, 22:15
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.Enginsight
| Vendor | Product | Version |
|---|---|---|
| zohocorp | manageengine_servicedesk_plus | 11.1 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11100 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11101 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11102 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11103 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11104 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11105 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11106 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11107 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11108 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11109 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11110 |
| zohocorp | manageengine_servicedesk_plus | 11.1:11111 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration