Privilege escalation vulnerability in query reports

CVE ID : CVE-2022-40772

Product NameSeverityAffected Version(s)Fixed Version(s)Fixed On
ServiceDesk PlusMedium14000 and below14001Oct. 14, 2022
ServiceDesk Plus MSPMedium10608 and below10609Sept. 26, 2022
SupportCenter PlusMedium11024 and below11025Oct. 13, 2022
AssetExplorerMedium6980 and below6981Oct. 13, 2022

Details

This vulnerability allows an adversary to access restricted data in the Postgres database setup by using a specific PostgreSQL function in the query, which enables bypassing the validation mechanism.

Impact

Users who have access to query reports can access restricted data.

Steps to upgrade

  1. Download the latest upgrade pack from the following links for the respective products:
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above links.

Acknowledgements

This vulnerability was reported by Piotr Bazydlo (@chudypb) of Trend Micro's Zero Day Initiative.

If you have any questions or concerns, please contact product support for further details at the below-mentioned email addresses.

ServiceDesk Plus: support@servicedeskplus.com

ServiceDesk Plus MSP: support@servicedeskplusmsp.com

SupportCenter Plus: support@supportcenterplus.com

AssetExplorer: assetexplorer-support@manageengine.com

Let's support faster, easier, and together