Lucene search

K
cveMitreCVE-2022-40771
HistoryNov 23, 2022 - 6:15 p.m.

CVE-2022-40771

2022-11-2318:15:12
CWE-611
mitre
web.nvd.nist.gov
36
2
zoho
manageengine
servicedesk plus
cve-2022-40771
vulnerability
xml external entity attack
information disclosure

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

38.5%

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.

Affected configurations

Nvd
Node
zohocorpmanageengine_servicedesk_plusRange<14.0
OR
zohocorpmanageengine_servicedesk_plusMatch14.0-
OR
zohocorpmanageengine_servicedesk_plusMatch14.014000
Node
zohocorpmanageengine_servicedesk_plus_mspRange<13.0
OR
zohocorpmanageengine_servicedesk_plus_mspMatch13.0-
OR
zohocorpmanageengine_servicedesk_plus_mspMatch13.013000
Node
zohocorpmanageengine_supportcenter_plusRange<11.0
OR
zohocorpmanageengine_supportcenter_plusMatch11.0-
OR
zohocorpmanageengine_supportcenter_plusMatch11.011000
OR
zohocorpmanageengine_supportcenter_plusMatch11.011001
OR
zohocorpmanageengine_supportcenter_plusMatch11.011002
OR
zohocorpmanageengine_supportcenter_plusMatch11.011003
OR
zohocorpmanageengine_supportcenter_plusMatch11.011004
OR
zohocorpmanageengine_supportcenter_plusMatch11.011005
OR
zohocorpmanageengine_supportcenter_plusMatch11.011006
OR
zohocorpmanageengine_supportcenter_plusMatch11.011007
OR
zohocorpmanageengine_supportcenter_plusMatch11.011008
OR
zohocorpmanageengine_supportcenter_plusMatch11.011009
OR
zohocorpmanageengine_supportcenter_plusMatch11.011010
OR
zohocorpmanageengine_supportcenter_plusMatch11.011011
OR
zohocorpmanageengine_supportcenter_plusMatch11.011012
OR
zohocorpmanageengine_supportcenter_plusMatch11.011013
OR
zohocorpmanageengine_supportcenter_plusMatch11.011014
OR
zohocorpmanageengine_supportcenter_plusMatch11.011015
OR
zohocorpmanageengine_supportcenter_plusMatch11.011016
OR
zohocorpmanageengine_supportcenter_plusMatch11.011017
OR
zohocorpmanageengine_supportcenter_plusMatch11.011018
OR
zohocorpmanageengine_supportcenter_plusMatch11.011019
OR
zohocorpmanageengine_supportcenter_plusMatch11.011020
OR
zohocorpmanageengine_supportcenter_plusMatch11.011021
OR
zohocorpmanageengine_supportcenter_plusMatch11.011022
OR
zohocorpmanageengine_supportcenter_plusMatch11.011024
OR
zohocorpmanageengine_supportcenter_plusMatch11.011025
Node
zohocorpmanageengine_assetexplorerRange<6.9
OR
zohocorpmanageengine_assetexplorerMatch6.9-
OR
zohocorpmanageengine_assetexplorerMatch6.96900
OR
zohocorpmanageengine_assetexplorerMatch6.96901
OR
zohocorpmanageengine_assetexplorerMatch6.96902
OR
zohocorpmanageengine_assetexplorerMatch6.96903
OR
zohocorpmanageengine_assetexplorerMatch6.96904
OR
zohocorpmanageengine_assetexplorerMatch6.96905
OR
zohocorpmanageengine_assetexplorerMatch6.96906
OR
zohocorpmanageengine_assetexplorerMatch6.96907
OR
zohocorpmanageengine_assetexplorerMatch6.96908
OR
zohocorpmanageengine_assetexplorerMatch6.96909
OR
zohocorpmanageengine_assetexplorerMatch6.96950
OR
zohocorpmanageengine_assetexplorerMatch6.96951
OR
zohocorpmanageengine_assetexplorerMatch6.96952
OR
zohocorpmanageengine_assetexplorerMatch6.96953
OR
zohocorpmanageengine_assetexplorerMatch6.96954
OR
zohocorpmanageengine_assetexplorerMatch6.96955
OR
zohocorpmanageengine_assetexplorerMatch6.96956
OR
zohocorpmanageengine_assetexplorerMatch6.96957
OR
zohocorpmanageengine_assetexplorerMatch6.96970
OR
zohocorpmanageengine_assetexplorerMatch6.96971
OR
zohocorpmanageengine_assetexplorerMatch6.96972
OR
zohocorpmanageengine_assetexplorerMatch6.96973
OR
zohocorpmanageengine_assetexplorerMatch6.96974
OR
zohocorpmanageengine_assetexplorerMatch6.96975
OR
zohocorpmanageengine_assetexplorerMatch6.96976
OR
zohocorpmanageengine_assetexplorerMatch6.96977
OR
zohocorpmanageengine_assetexplorerMatch6.96978
OR
zohocorpmanageengine_assetexplorerMatch6.96979
OR
zohocorpmanageengine_assetexplorerMatch6.96980
VendorProductVersionCPE
zohocorpmanageengine_servicedesk_plus*cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:*:*:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus14.0cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.0:-:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus14.0cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:14.0:14000:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus_msp*cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:*:*:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus_msp13.0cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:13.0:-:*:*:*:*:*:*
zohocorpmanageengine_servicedesk_plus_msp13.0cpe:2.3:a:zohocorp:manageengine_servicedesk_plus_msp:13.0:13000:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus*cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:*:*:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus11.0cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:-:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus11.0cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11000:*:*:*:*:*:*
zohocorpmanageengine_supportcenter_plus11.0cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11001:*:*:*:*:*:*
Rows per page:
1-10 of 641

Social References

More

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

38.5%

Related for CVE-2022-40771