CVE-2022-40772

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
VendorProductVersion
zohocorpmanageengine_servicedesk_plus
𝑥
< 14.0
zohocorpmanageengine_servicedesk_plus
14.0
zohocorpmanageengine_servicedesk_plus
14.0:14000
zohocorpmanageengine_servicedesk_plus_msp
𝑥
< 10.6
zohocorpmanageengine_servicedesk_plus_msp
10.6
zohocorpmanageengine_servicedesk_plus_msp
10.6:10600
zohocorpmanageengine_servicedesk_plus_msp
10.6:10601
zohocorpmanageengine_servicedesk_plus_msp
10.6:10602
zohocorpmanageengine_servicedesk_plus_msp
10.6:10603
zohocorpmanageengine_servicedesk_plus_msp
10.6:10604
zohocorpmanageengine_servicedesk_plus_msp
10.6:10605
zohocorpmanageengine_servicedesk_plus_msp
10.6:10606
zohocorpmanageengine_servicedesk_plus_msp
10.6:10607
zohocorpmanageengine_servicedesk_plus_msp
10.6:10608
zohocorpmanageengine_supportcenter_plus
𝑥
< 11.0
zohocorpmanageengine_supportcenter_plus
11.0
zohocorpmanageengine_supportcenter_plus
11.0:11000
zohocorpmanageengine_supportcenter_plus
11.0:11001
zohocorpmanageengine_supportcenter_plus
11.0:11002
zohocorpmanageengine_supportcenter_plus
11.0:11003
zohocorpmanageengine_supportcenter_plus
11.0:11004
zohocorpmanageengine_supportcenter_plus
11.0:11005
zohocorpmanageengine_supportcenter_plus
11.0:11006
zohocorpmanageengine_supportcenter_plus
11.0:11007
zohocorpmanageengine_supportcenter_plus
11.0:11008
zohocorpmanageengine_supportcenter_plus
11.0:11009
zohocorpmanageengine_supportcenter_plus
11.0:11010
zohocorpmanageengine_supportcenter_plus
11.0:11011
zohocorpmanageengine_supportcenter_plus
11.0:11012
zohocorpmanageengine_supportcenter_plus
11.0:11013
zohocorpmanageengine_supportcenter_plus
11.0:11014
zohocorpmanageengine_supportcenter_plus
11.0:11015
zohocorpmanageengine_supportcenter_plus
11.0:11016
zohocorpmanageengine_supportcenter_plus
11.0:11017
zohocorpmanageengine_supportcenter_plus
11.0:11018
zohocorpmanageengine_supportcenter_plus
11.0:11019
zohocorpmanageengine_supportcenter_plus
11.0:11020
zohocorpmanageengine_supportcenter_plus
11.0:11021
zohocorpmanageengine_supportcenter_plus
11.0:11022
zohocorpmanageengine_supportcenter_plus
11.0:11024
zohocorpmanageengine_assetexplorer
𝑥
< 6.9
zohocorpmanageengine_assetexplorer
6.9
zohocorpmanageengine_assetexplorer
6.9:6900
zohocorpmanageengine_assetexplorer
6.9:6901
zohocorpmanageengine_assetexplorer
6.9:6902
zohocorpmanageengine_assetexplorer
6.9:6903
zohocorpmanageengine_assetexplorer
6.9:6904
zohocorpmanageengine_assetexplorer
6.9:6905
zohocorpmanageengine_assetexplorer
6.9:6906
zohocorpmanageengine_assetexplorer
6.9:6907
zohocorpmanageengine_assetexplorer
6.9:6908
zohocorpmanageengine_assetexplorer
6.9:6909
zohocorpmanageengine_assetexplorer
6.9:6950
zohocorpmanageengine_assetexplorer
6.9:6951
zohocorpmanageengine_assetexplorer
6.9:6952
zohocorpmanageengine_assetexplorer
6.9:6953
zohocorpmanageengine_assetexplorer
6.9:6954
zohocorpmanageengine_assetexplorer
6.9:6955
zohocorpmanageengine_assetexplorer
6.9:6956
zohocorpmanageengine_assetexplorer
6.9:6957
zohocorpmanageengine_assetexplorer
6.9:6970
zohocorpmanageengine_assetexplorer
6.9:6971
zohocorpmanageengine_assetexplorer
6.9:6972
zohocorpmanageengine_assetexplorer
6.9:6973
zohocorpmanageengine_assetexplorer
6.9:6974
zohocorpmanageengine_assetexplorer
6.9:6975
zohocorpmanageengine_assetexplorer
6.9:6976
zohocorpmanageengine_assetexplorer
6.9:6977
zohocorpmanageengine_assetexplorer
6.9:6978
zohocorpmanageengine_assetexplorer
6.9:6979
zohocorpmanageengine_assetexplorer
6.9:6980
𝑥
= Vulnerable software versions