Issues Fixed in 9415

Vulnerability :

  • SD-72109 : XSS vulnerability found in the asset details page is fixed.
  • SD-71576 : XSS vulnerability found in Change Calendar is fixed.
  • SD-72080 : Directory traversal vulnerability found in file upload is fixed.
  • SD-71495 : ZipSlip vulnerability found in distributed asset scan is fixed.
  • SD-72568 : Vulnerability in deletion of default license types is fixed.
  • SD-68282 : No alert message is displayed, warning about the impacted scan types when we enable “Stop uploading scanned XMLs via non-login URL” under the Security Settings.
  • SD-71928 : Privilege Escalation Vulnerability in project module Gantt view.
  • SD-69108 : Security response headers are missing in the login form.
  • SD-71704, 71703, 71702, 71676, 71675, 71674 : GET URLs replaced with POST URLs.
  • SD-71595 : Vulnerability : Able to create a table and copy data in MSSQL.
  • SD-66826 : Vulnerable HTTP method (OPTIONS) disabled.

Requests :

  • SD-72141 : In the request history, Before Modification and After Modification sections with regards to Description changes are not displayed.

Assets :

  • SD-71491, 71490 : Failure exception message displayed during network scan is fixed.
Build Release

You may be interested in these other recent articles

27 Nov

Last Week’s Best ManageEngine Updates – Part 29

27 November 2023 | Nazim Nadir


Exciting news of ManageEngine Linkedin Live webinar has been announced alongside some application updates and the release of a new E-Book. Whether you’re new to…

Read more
30 Oct

Last Week’s Best ManageEngine Updates – Part 28

30 October 2023 | Nazim Nadir


Updates on stability have been made by ManageEngine to enhance your end-user experience with their products. Continue reading to learn which ManageEngine applications gain the…

Read more
23 Oct

Last Week’s Best ManageEngine Updates – Part 27

23 October 2023 | Nazim Nadir


The ManageEngine application suite will soon receive some new additions and improvements. A new E-book from the Analytics Plus team has also been published, and…

Read more