CVE Vulnerabilities

CVE-2011-1509

Published: Sep 20, 2011 | Modified: Oct 09, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

Affected Software

Name Vendor Start Version End Version
Servicedesk_plus Manageengine * 8012 (including)
Servicedesk_plus Manageengine 8.0 (including) 8.0 (including)

References