vendor:
ServiceDesk Plus
by:
Operat0r
4.3
CVSS
MEDIUM
User enumeration vulnerability
200
CWE
Product Name: ServiceDesk Plus
Affected Version From: 9.3
Affected Version To: 9.3
Patch Exists: YES
Related CWE: CVE-2019-10273
CPE: a:manageengine:servicedesk_plus:9.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu Linux
2019
ManageEngine ServiceDesk Plus – 9.3 User enumeration vulnerability
CVE-2019-10273 is a information leakage vulnerability within the ManageEngine ServiceDesk Plus 9.3 software, this vulnerability allows for the enumeration of active users that are registered on the ServiceDesk 9.3 hosted software. Due to a flaw within the way the authentication is handled, an attacked is able to login and verify any active account.
Mitigation:
Ensure that authentication is handled securely and that user enumeration is not possible.