Command Injection in Zoho ManageEngine ServiceDesk Plus - CVE-2022-40770

 

Command Injection in Zoho ManageEngine ServiceDesk Plus - CVE-2022-40770

Published: November 24, 2022


Vulnerability identifier: #VU69556
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40770
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the system.

The vulnerability exists due to improper input validation within the invokeDataUploadTool() function when handling data passed via the fields required to configure the Analytics Plus integration. A remote privileged user can inject and execute arbitrary commands on the system.


Affected software

Zoho ManageEngine ServiceDesk Plus
Zoho ManageEngine ServiceDesk Plus MSP
Zoho ManageEngine SupportCenter Plus

How to mitigate CVE-2022-40770

Install updates from vendor's website.

Zoho ManageEngine ServiceDesk Plus - update to 13.0 13011
Zoho ManageEngine ServiceDesk Plus MSP - update to 13000
Zoho ManageEngine SupportCenter Plus - update to 11026

External References

Related Security Bulletins