RULE(RULE ID:321793)

Rule General Information
Release Date: 2019-06-10
Rule Name: ManageEngine ServiceDesk DownloadFileServlet Information Disclosure Vulnerability (CVE-2017-11511)
Severity:
CVE ID:
Rule Protection Details
Description: The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:101788
https://www.tenable.com/security/research/tra-2017-31
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.manageengine.com