Insufficient Logging in Zoho ManageEngine ServiceDesk Plus - #VU74788

 

Insufficient Logging in Zoho ManageEngine ServiceDesk Plus - #VU74788

Published: April 11, 2023


Vulnerability identifier: #VU74788
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-778
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conceal their activity.

The vulnerability exists due to authorization token is not logged if it is passed via HTTP headers. A remote attacker can conceal their activity within the application by sending the authorization token via HTTP header.


Affected software

Zoho ManageEngine ServiceDesk Plus

Remediation

Install updates from vendor's website.

Zoho ManageEngine ServiceDesk Plus - update to 14.2 14201

External References

Related Security Bulletins