← Back

CVE-2022-40772

nvd nist
Published: Nov 23, 2022Modified: Apr 28, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.

Affected (71)

4 products
Manageengine Servicedesk Plus
Manageengine Servicedesk Plus Msp
Manageengine Supportcenter Plus
Manageengine Assetexplorer
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 14.0
Version 14.0
Version 14.0 14000
Configuration B
11 vulnerable
Configuration C
26 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 11.0
Version 11.0
Version 11.0 11000
Version 11.0 11001
Version 11.0 11002
Version 11.0 11003
Version 11.0 11004
Version 11.0 11005
Version 11.0 11006
Version 11.0 11007
Version 11.0 11008
Version 11.0 11009
Version 11.0 11010
Version 11.0 11011
Version 11.0 11012
Version 11.0 11013
Version 11.0 11014
Version 11.0 11015
Version 11.0 11016
Version 11.0 11017
Version 11.0 11018
Version 11.0 11019
Version 11.0 11020
Version 11.0 11021
Version 11.0 11022
Version 11.0 11024
Configuration D
31 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 6.9
Version 6.9
Version 6.9 6900
Version 6.9 6901
Version 6.9 6902
Version 6.9 6903
Version 6.9 6904
Version 6.9 6905
Version 6.9 6906
Version 6.9 6907
Version 6.9 6908
Version 6.9 6909
Version 6.9 6950
Version 6.9 6951
Version 6.9 6952
Version 6.9 6953
Version 6.9 6954
Version 6.9 6955
Version 6.9 6956
Version 6.9 6957
Version 6.9 6970
Version 6.9 6971
Version 6.9 6972
Version 6.9 6973
Version 6.9 6974
Version 6.9 6975
Version 6.9 6976
Version 6.9 6977
Version 6.9 6978
Version 6.9 6979
Version 6.9 6980

References (4)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.