PT-2011-12: Information Disclosure in ManageEngine ServiceDesk Plus 8.0 Vulnerable softwareManageEngine ServiceDesk Plus Version: 8.0 (8019) and earlier Application link: http://www.servicedeskplus.comSeverity levelSeverity level: Medium Impact: Application Database Access Access Vector: Network exploitable CVSS v2: Base Score: 6.3 Vector: (AV:N/AC:M/Au:S/C:C/I:N/A:N)CVE: not assignedSoftware descriptionManageEngine ServiceDesk Plus is a technical support and assests management system.Vulnerability descriptionPositive Research Center has discovered an information disclosure in ManageEngine ServiceDesk Plus.Incorrect privilege validation allows attackers with guest privileges (account guest/guest) to modify backup rights and use these new rights to create a backup copy in any folder. How to fixUpdate your software up to the latest version Advisory status24.06.2011 - Vendor is notified 28.06.2011 - Vendor gets vulnerability details 29.11.2011 - Vendor releases fixed version and details 27.01.2012 - Public disclosureCreditsThe vulnerability was discovered by Alexander Zaitsev, Positive Research Center (Positive Technologies Company)Referenceshttp://en.securitylab.ru/lab/PT-2011-12Reports on the vulnerabilities previously discovered by Positive Research:http://www.ptsecurity.com/advisory1.aspx http://en.securitylab.ru/lab/