ManageEngine Desktop Central Vulnerabilities
ID: 80648784-f94b-5c33-b340-1a0367fecc92
STIX ID: report--80648784-f94b-5c33-b340-1a0367fecc92
Feed Name: NCC Research
NCC Group disclosed multiple critical vulnerabilities in ManageEngine Desktop Central that permit unauthenticated SQL queries and file-upload/traversal abuses leading to remote code execution as NT AUTHORITY\SYSTEM on servers hosting the web interface (affecting versions <= 10.0.184). The advisory documents vulnerable endpoints (/jsp/admin/DBQueryExecutor.jsp and /inventoryScript.do), exploitation techniques (including using PostgreSQL COPY to write web-accessible JSPs), impact on managed endpoints, and recommends upgrading to build 10.0.208 or later and applying least-privilege and server-side validation mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
