Insufficient Logging in Zoho ManageEngine ServiceDesk Plus - #VU74788
Published: April 11, 2023
Vulnerability identifier: #VU74788
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-778
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conceal their activity.
The vulnerability exists due to authorization token is not logged if it is passed via HTTP headers. A remote attacker can conceal their activity within the application by sending the authorization token via HTTP header.
Affected software
Zoho ManageEngine ServiceDesk Plus
Remediation
Install updates from vendor's website.
Zoho ManageEngine ServiceDesk Plus - update to 14.2 14201