CVE-2016-4889

CWE-2643 documents3 sources
Severity
8.8HIGH
EPSS
4.3%
top 11.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateMay 17

Description

ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-3p82-57h4-gc59: ZOHO ManageEngine ServiceDesk Plus before 92022-05-17
CVEList
CVE-2016-4889: ZOHO ManageEngine ServiceDesk Plus before 92017-04-14
CVE-2016-4889 (HIGH CVSS 8.8) | ZOHO ManageEngine ServiceDesk Plus | cvebase.io