VulnerabilityModified
CVE-2018-7248
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317.
MEDIUM 5.3EPSS 6.35%
Does this matter?
Lower severity and a low EPSS score (6.35%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 6.35% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- zohocorp/manageengine servicedesk plus
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/104287Third Party Advisory, VDB Entry
- https://gitlab.com/e-sterling/cve-2018-7248Exploit, Third Party Advisory
- https://medium.com/%40esterling_/cve-2018-7248-enumerating-active-directory-users-via-unauthenticated-manageengine-servicedesk-a1eda2942eb0
- http://www.securityfocus.com/bid/104287Third Party Advisory, VDB Entry
- https://gitlab.com/e-sterling/cve-2018-7248Exploit, Third Party Advisory
- https://medium.com/%40esterling_/cve-2018-7248-enumerating-active-directory-users-via-unauthenticated-manageengine-servicedesk-a1eda2942eb0
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.