CVE-2016-4890

CWE-2543 documents3 sources
Severity
5.3MEDIUM
EPSS
3.0%
top 13.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 14
Latest updateMay 17

Description

ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-h2jg-xqpm-gpc5: ZOHO ManageEngine ServiceDesk Plus before 92022-05-17
CVEList
CVE-2016-4890: ZOHO ManageEngine ServiceDesk Plus before 92017-04-14
CVE-2016-4890 (MEDIUM CVSS 5.3) | ZOHO ManageEngine ServiceDesk Plus | cvebase.io