CVE-2015-1480

ZOHO ManageEngine ServiceDesk Plus <9.0 build 9031 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-1480. PoCs published by Rewterz - Research Group.

AI-analyzed exploit summary This advisory describes an improper privilege management vulnerability in ManageEngine ServiceDesk Plus, allowing low-privileged users to access administrative data. The PoC includes URLs demonstrating unauthorized access to ticket data and reports.

Description

ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a direct request to (2) swf/flashreport.swf, (3) reports/flash/details.jsp, or (4) reports/CreateReportTable.jsp.

Exploits (1)

exploitdb WRITEUP
by Rewterz - Research Group · textwebappsjsp
https://www.exploit-db.com/exploits/35904

This advisory describes an improper privilege management vulnerability in ManageEngine ServiceDesk Plus, allowing low-privileged users to access administrative data. The PoC includes URLs demonstrating unauthorized access to ticket data and reports.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ManageEngine ServiceDesk Plus 9.0
Auth required
Prerequisites: Valid low-privileged user credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/117499
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35904
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72302
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534538/100/0/threaded

Scores

EPSS 0.0626
EPSS Percentile 92.7%

Details

CWE
CWE-200
Status published
Products (1)
manageengine/servicedesk_plus < 9.0
Published Feb 04, 2015
Tracked Since Feb 18, 2026