Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
References
Link | Resource |
---|---|
https://www.manageengine.com/products/desktop-central/unauthenticated-servlet-access.html | Vendor Advisory |
Configurations
Information
Published : 2020-03-30 11:15
Updated : 2022-04-06 09:29
NVD link : CVE-2020-8509
Mitre link : CVE-2020-8509
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
zohocorp
- manageengine_desktop_central