This is a security advisory for ServiceDesk Plus MSP customers using versions 9302 or earlier. We recommend that you upgrade to the latest version of ServiceDesk Plus MSP, 9305, to fix the security vulnerability described below.
Description: ServiceDesk Plus MSP contained a vulnerability through which it was possible to upload files using an unauthenticated servlet. This was identified and disclosed by Digital Defense, a provider of security risk assessment solutions. For details, please refer to the public disclosure published on January 30th.
Severity: Very High
Affects: ServiceDesk Plus MSP customers using version 9302 or earlier.
Background: Digital Defense responsibly disclosed the vulnerability to ManageEngine in November of 2017. Shortly afterwards, our security and development teams touched base with Digital Defense to gather more information. We accord the highest priority to fixing vulnerabilities, and this particular vulnerability was addressed on January 11th with an update to ServiceDesk Plus MSP (version 9305).
Next Steps: Download the upgrade pack from https://www.manageengine.com/products/service-desk/service-packs.html and immediately upgrade to the latest version (9305). Please read the upgrade instructions carefully before beginning the upgrade. For assistance, write to email@example.com or or call us toll-free at +1.888.720.9500.
Important Note: As always, make a copy of the entire ServiceDesk Plus MSP installation folder before applying the upgrade and keep the copy in a separate location. If anything goes wrong during the upgrade, you'll have this copy as a backup, which will keep all your settings intact. If you're using a MS SQL server as a back-end database, back up the ServiceDesk Plus MSP database before applying the upgrade. Once the upgrade is successfully completed, remember to delete the backup.
We offer our sincerest apologies for any inconvenience this may have caused.
ServiceDesk Plus MSP team.