CVE-2022-35403: Zohocorp ManageEngine Assetexplorer
High severity, CVSS 7.5. EPSS: 6.2% chance of exploitation in the next 30 days.
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)
Affected products
- Zohocorp ManageEngine Assetexplorer: before 6.9 (fixed in 6.9); version 6.9 only
- Zohocorp ManageEngine ServiceDesk Plus: before 13.0 (fixed in 13.0); version 13.0 only
- Zohocorp ManageEngine ServiceDesk Plus Msp: before 10.6 (fixed in 10.6); version 10.6 only
- Zohocorp ManageEngine SupportCenter Plus: before 11.0 (fixed in 11.0); version 11.0 only
Published 2022-07-12. Last modified 2026-06-17.