CVE-2017-9362: Zohocorp ManageEngine ServiceDesk Plus

High severity, CVSS 8.8. EPSS: 4.1% chance of exploitation in the next 30 days.

ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

Affected products

  • Zohocorp ManageEngine ServiceDesk Plus: before 9.3 (fixed in 9.3)

Published 2019-03-25. Last modified 2026-06-17.