CVE

Id
91709  
CVE No.
CVE-2016-4890  
Status
Candidate  
Description
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.  
Phase
Assigned (20160517)  
Votes
None (candidate not yet proposed)  
Comments