CISA Known Exploited Vulnerability

CVE-2019-8394

Zoho · ManageEngine

Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

Date added
BOD 22-01 due date
CWE CWE-434
Ransomware Unknown

CISA description

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

Required action

Apply updates per vendor instructions.