Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.manageengine.com/products/desktop-central/unauthorized-admin-credential-modification.html | vendor advisory |
http://packetstormsecurity.com/files/131062/Manage-Engine-Desktop-Central-9-Unauthorized-Administrative-Password-Reset.html | exploit vdb entry third party advisory |
http://www.securityfocus.com/archive/1/535004/100/1400/threaded | mailing list |
http://www.securityfocus.com/bid/73380 | vdb entry third party advisory |