Vulnerability Description
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zohocorp | Manageengine Servicedesk Plus Msp | >= 8.0, <= 9.4 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/163192/Zoho-ManageEngine-ServiceDesk-Plus-9ExploitThird Party AdvisoryVDB Entry
- https://github.com/ricardojoserf/CVE-2021-31159ExploitThird Party Advisory
- https://www.manageengine.comProduct
- https://www.manageengine.com/products/service-desk-msp/readme.html#10519Release NotesVendor Advisory
- http://packetstormsecurity.com/files/163192/Zoho-ManageEngine-ServiceDesk-Plus-9ExploitThird Party AdvisoryVDB Entry
- https://github.com/ricardojoserf/CVE-2021-31159ExploitThird Party Advisory
- https://www.manageengine.comProduct
- https://www.manageengine.com/products/service-desk-msp/readme.html#10519Release NotesVendor Advisory
FAQ
What is CVE-2021-31159?
CVE-2021-31159 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
How severe is CVE-2021-31159?
CVE-2021-31159 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31159?
Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Servicedesk Plus Msp.