ZeroHour

CVE-2016-4890

CVSS 3.0
5.3 medium
EPSS
3%p88
Published
()
Modified
Description

ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.

Vendors
zohocorp
Products
servicedesk plus
Weakness
CWE-254
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.