ManageEngine.ServiceDesk.DownloadSnapshotServlet.Path.Traversal

description-logoDescription

This indicates an attack attempt to exploit an Information Disclosure vulnerability in ManageEngine ServiceDesk.
The vulnerability is due to an error in the vulnerable application when handling a maliciously crafted request. An attacker can exploit this to disclose arbitrary files on the affected machine via a crafted request.

affected-products-logoAffected Products

Zoho Corporation ManageEngine ServiceDesk 9.3 build 9333 and prior

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems

recomended-action-logoRecommended Actions

Currently we are unaware of any vendor supplied patch or updates available for this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)