Vulnerability record · CVE-2017-11512 · published 8 November 2017
CVE-2017-11512: ManageEngine ServiceDesk path traversal allows arbitrary file download
Manageengine · Servicedesk
ManageEngine ServiceDesk 9.3.9328 fails to properly restrict the pathname in the name parameter of the download-snapshot URL, allowing path traversal. An unauthenticated remote attacker can download arbitrary files from the server, exposing sensitive data such as configuration files, credentials, or system files.
Description
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 high severity, unauthenticated remote file read, and very high EPSS score despite no KEV listing.
What it is
ManageEngine ServiceDesk 9.3.9328 fails to properly restrict the pathname in the name parameter of the download-snapshot URL, allowing path traversal. An unauthenticated remote attacker can download arbitrary files from the server, exposing sensitive data such as configuration files, credentials, or system files.
Impact
An attacker can read arbitrary files on the host, leading to disclosure of sensitive information that may enable further compromise. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP requests to the download-snapshot endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit references are tagged; EPSS is high (0.796, 99.6th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the vendor patch or upgrade ServiceDesk to a fixed version as soon as possible.
- Restrict network access to the ServiceDesk web interface to trusted networks or VPN.
- Validate and sanitize the name parameter to prevent path traversal sequences.
- Run the ServiceDesk service with least privilege to limit file exposure.
Detection
- Monitor web logs for requests to download-snapshot with path traversal patterns (e.g., ../, encoded variants).
- Alert on unusual file access or downloads from the ServiceDesk process.
- Review outbound traffic for exfiltration of sensitive files from the server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101789 | Third Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2017-31 | Issue TrackingThird Party Advisory |
| http://www.securityfocus.com/bid/101789 | Third Party AdvisoryVDB Entry |
| https://www.tenable.com/security/research/tra-2017-31 | Issue TrackingThird Party Advisory |
Track CVE-2017-11512 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11512), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.