← Back

CVE-2022-40773

nvd nist
Published: Nov 12, 2022Modified: May 1, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.

Affected (37)

2 products
Manageengine Servicedesk Plus Msp
Manageengine Supportcenter Plus
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Zohocorp
Before 10.6
Version 10.6
Version 10.6 10600
Version 10.6 10601
Version 10.6 10602
Version 10.6 10603
Version 10.6 10604
Version 10.6 10605
Version 10.6 10606
Version 10.6 10607
Version 10.6 10608
Zohocorp
Before 11.0
Version 11.0
Version 11.0 11000
Version 11.0 11001
Version 11.0 11002
Version 11.0 11003
Version 11.0 11004
Version 11.0 11005
Version 11.0 11006
Version 11.0 11007
Version 11.0 11008
Version 11.0 11009
Version 11.0 11010
Version 11.0 11011
Version 11.0 11012
Version 11.0 11013
Version 11.0 11014
Version 11.0 11015
Version 11.0 11016
Version 11.0 11017
Version 11.0 11018
Version 11.0 11019
Version 11.0 11020
Version 11.0 11021
Version 11.0 11022
Version 11.0 11024

References (4)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.