CVE-2016-4890: Zohocorp ServiceDesk Plus

Medium severity, CVSS 5.3. EPSS: 3.5% chance of exploitation in the next 30 days.

ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.

Affected products

  • Zohocorp ServiceDesk Plus: up to and including 9.1

Published 2017-04-14. Last modified 2026-06-17.