Medium severity5.3NVD Advisory· Published Aug 21, 2019· Updated Jun 17, 2026
CVE-2019-15045
CVE-2019-15045
Description
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:zohocorp:manageengine_servicedesk_plus:*:*:*:*:*:*:*:*Range: >=10,<10509
- Zoho/ManageEngine ServiceDesk Plusdescription
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/154183/Zoho-Corporation-ManageEngine-ServiceDesk-Plus-Information-Disclosure.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2019/Aug/17nvdExploitMailing ListThird Party Advisory
- www.manageengine.com/products/service-desk/readme.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.