CVE-2019-8394

MEDIUM(6.5)KEVLikely Exploited

Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

Description

CVE-2019-8394 is a medium-severity arbitrary file upload vulnerability in Zoho ManageEngine ServiceDesk Plus, an enterprise IT help desk and asset management platform. The vulnerability allows remote authenticated attackers to upload arbitrary files through the login page customization feature in versions before 10.0 build 10012. By exploiting CVE-2019-8394, an attacker with low-level privileges can upload malicious files to the server, potentially achieving code execution or replacing legitimate application files. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. With an EPSS score of 87.28% (99.45th percentile), this Zoho ManageEngine ServiceDesk Plus vulnerability poses a significant risk to organizations running unpatched instances.

KEV Information

Vendor
Zoho
Product
ManageEngine
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
zohocorpmanageengine servicedesk plus< 10.0.0; 10.0.0

Multiple CVSS Assessments

Source: [email protected](Primary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.5
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

Weakness Type

CWE-434: Unrestricted Upload of File with Dangerous Type

CWE-434 occurs when an application allows users to upload files without properly restricting the file type, size, or content, enabling attackers to upload executable code or other dangerous file types. In CVE-2019-8394, the Zoho ManageEngine ServiceDesk Plus login page customization feature fails to properly validate uploaded files, allowing authenticated attackers to upload arbitrary files including potentially executable content.

Learn more: CWE-434 — Unrestricted Upload of File with Dangerous Type

Impact Analysis

CVE-2019-8394 carries a CVSS 3.1 score of 6.5 (MEDIUM), reflecting a network-exploitable vulnerability with low attack complexity that requires low-level authentication but no user interaction. The primary impact is on integrity, rated as HIGH, meaning an attacker can upload and modify files on the server without restriction. While confidentiality and availability impacts are rated as NONE in the primary CVSS assessment, the ability to upload arbitrary files could lead to secondary impacts such as remote code execution if executable files are placed in web-accessible directories. The EPSS score of 87.28% (99.45th percentile) indicates a very high probability of exploitation activity, significantly exceeding what the moderate CVSS score might suggest. Organizations using ServiceDesk Plus as their central IT help desk platform should prioritize remediation given the confirmed active exploitation.

Exploit Maturity

CVE-2019-8394 has a mature exploit landscape with confirmed active exploitation. CISA has confirmed active exploitation in the wild through its KEV catalog listing. Public exploit code is available via Exploit-DB, providing detailed proof-of-concept code that demonstrates the arbitrary file upload attack through the login page customization feature. The EPSS score of 87.28% (99.45th percentile) indicates a very high probability of exploitation activity. Federal agencies were required to remediate this vulnerability by 2022-05-03 per CISA binding operational directive.

Remediation

  1. Apply updates immediately as mandated by CISA KEV: Apply updates per vendor instructions. Upgrade Zoho ManageEngine ServiceDesk Plus to version 10.0 build 10012 or later using the official patch referenced in the ManageEngine release notes.
  2. Verify that all instances of ManageEngine ServiceDesk Plus (versions prior to 10.0 build 10012, as well as version 10.0.0 builds prior to 10012) have been updated. Check the build number in the ServiceDesk Plus admin console.
  3. If immediate patching is not possible, restrict access to the login page customization functionality. Limit administrative access to ServiceDesk Plus to trusted internal IP addresses and disable external access to the management interface.
  4. Review server file systems for unauthorized or suspicious files that may have been uploaded through the customization feature. Check web-accessible directories for unexpected executable files, scripts, or webshells.
  5. Implement long-term hardening measures including file upload validation at the application and WAF level, restricting uploaded file types to only whitelisted extensions, enforcing file content-type verification, and storing uploaded files outside the web root directory to prevent direct execution.

Technical Details

CVE-2019-8394 exploits a file upload vulnerability classified under CWE-434 (Unrestricted Upload of File with Dangerous Type) in Zoho ManageEngine ServiceDesk Plus versions before 10.0 build 10012. The vulnerability resides in the login page customization feature, which allows authenticated users to upload files to customize the appearance of the ServiceDesk Plus login page but fails to properly validate the type and content of uploaded files. The CVSS vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N indicates that exploitation is network-based with low complexity, requires only low-level privileges (a basic authenticated user account), and primarily impacts integrity by allowing unauthorized file modifications on the server. An attacker can abuse this functionality to upload arbitrary files, including server-side scripts or executable payloads, that could subsequently be accessed to achieve code execution on the underlying system.

Frequently Asked Questions

Is CVE-2019-8394 being actively exploited?

Yes. CVE-2019-8394 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Public exploit code is available on Exploit-DB, and the EPSS score of 87.28% (99.45th percentile) indicates a very high probability of exploitation activity.

What products are affected by CVE-2019-8394?

CVE-2019-8394 affects Zoho ManageEngine ServiceDesk Plus versions before 10.0 build 10012. This includes all earlier major versions as well as version 10.0.0 with builds prior to 10012.

How do I fix CVE-2019-8394?

Upgrade Zoho ManageEngine ServiceDesk Plus to version 10.0 build 10012 or later by applying the official vendor patch. If immediate patching is not possible, restrict access to the login page customization feature and review the file system for unauthorized uploads.

How severe is CVE-2019-8394?

CVE-2019-8394 has a CVSS 3.1 score of 6.5 (MEDIUM), though a secondary assessment rates it at 7.5 (HIGH). Despite the moderate primary CVSS rating, the EPSS score of 87.28% (99.45th percentile) and confirmed active exploitation indicate that this vulnerability poses a significant real-world threat requiring prompt remediation.

CVSS Score

6.5
MEDIUM(6.5)

EPSS Score

EPSS Score63.34%
EPSS Percentile99.1%

Dates

PublishedFebruary 17, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.