HTTP: Magane Engine Service Desk Inforamtion Disclosure

This signature detects attempts to exploit a known vulnerability against Manage Engine Service Desk.A Successful attack can lead to Information Disclosure.

Extended Description

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

Affected Products

Manageengine servicedesk

Short Name
HTTP:INFO:MANAGE-ENGINE-INF-DIS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2017-11511 Desk Disclosure Engine Inforamtion Magane Service bid:101788
Release Date
01/08/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Manageengine

CVSS Score

5.0

Found a potential security threat?