CVE-2015-2560
critical · 9.8Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
9.8
CVSS
15.2%
EPSS (exploit prob.)
97th
EPSS percentile
2017-08-02
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| zohocorp | manageengine_desktop_central | 9.0 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/131062/Manage-Engine-Desktop-Central-9-Unauthorized-Administrative-Password-Reset.html
- http://www.securityfocus.com/archive/1/535004/100/1400/threaded
- http://www.securityfocus.com/bid/73380
- https://www.manageengine.com/products/desktop-central/unauthorized-admin-credential-modification.html
- http://packetstormsecurity.com/files/131062/Manage-Engine-Desktop-Central-9-Unauthorized-Administrative-Password-Reset.html
- http://www.securityfocus.com/archive/1/535004/100/1400/threaded
- http://www.securityfocus.com/bid/73380
- https://www.manageengine.com/products/desktop-central/unauthorized-admin-credential-modification.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2015-2560