CVE-2016-4890
—CVSS 3.0
5.3 medium
EPSS
3%p88
Published
()
Modified
Description
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
- Vendors
- zohocorp
- Products
- servicedesk plus
- Weakness
- CWE-254
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.