Manage Engine Desktop Central agent enforcing specific type of browser only (silently Uninstall all non SOE)
My company has purchased Manage Engine Desktop central and deployed the agent in the production environment. In my previous experience with Microsoft SCCM, the agent can enforce only a specific list of browser that is allowed installed and running in the users PC like: Mozilla Firefox, Google Chrome, IE & Edge. Other than those white-listed browser, the agent will Uninstall it silently. is there any way in DesktopCentral v10 to enforce it that way? I look forward to your reply. Thanks.
Security Update - Ghostcat Vulnerability prevention for Desktop Central
A vulnerability with the name Ghostcat in Apache Tomcat (CVE 2020-1938), which is a third-party component used by Desktop Central was discovered by external security researchers of Chaitin Tech. This Ghostcat Vulnerability has been mitigated and has been released for ManageEngine Desktop Central. Follow the below given steps to prevent this vulnerability in Desktop Central Servers. Log in to your Desktop Central console, click on your current build number on the top right corner. You can find the
SNMP Traps not received by OpManager
Hello, I have issues with receiving traps in OpManager as no traps are currently displayed in OpManager v12.2. OpManager is installed on a Linux Centos 7 server. The following debugging steps has been taken: 1) A tcpdump on port 162 on the server running OpManager shows that the traps are being received correctly through the port so no issues with Firewalls 2) All devices are set with the correct credentials. 3) Trap definitions has been loaded through the mib files and enabled through the GUI.
CSV file to import assets
Dear All can you please share the CSV file to import assets. Regards
Failed to assign technician
I'm seeing something really weird here and I can't find any commonality. Occasionally, a ticket will simply fail to assign a technician. Here's an example. This is the ticket as it exists. I click on technician to assign it. Click the check mark to save it. I get the pop up that says it updated But the ticket remains unassigned: Help.
What's the value of Business View in CMDB?
We just upgraded to the latest build of SDP and I discovered Business View in CMDB. How does it work? What value your organization got from this feature?
ServiceDesk plus - Custom script
Hi, In the ServiceCatalogue you when you choose "Form and Fields" , is it possible to write a custom script that add a the requester to a Active Directory group when the form is submitted? kr Thomas
Security fix for CVE-2020-10189 - Remote Code Execution has been released!
Remote Access Plus was reported with a vulnerability that lets unauthenticated attackers execute arbitrary code on Remote Access Plus instances. This issue was reported by Steeven Seeley of Source Incite and is now been fixed. The security fix is released in build #10.0.452 and you can download the latest build from here. (or) 1. From your Remote Access Plus web console, click on your current build number in the top right corner. 2. You can find the latest build applicable to you. You can download
How to remove certificates
Hello, I have been trying for the last few days to get openssl working with untangle firewall openssl vpn server. Initially i uploaded some certs but i believe i had to upload all three certs: client, key and ca cert. So i was looking to upload a pk12 cert but i am now getting an error saying cert already exist. How do i delete the certs i have already uploaded and also is there a document on how we should setup openssl vpn? We are looking to deploy this to 500+ devices and now trying to get this
Unauthenticated remote code execution vulnerability fixed
Hello Everyone, The fix for Remote Code Execution vulnerability in Patch Manager Plus has been released in the build 100426 This hotfix is available at https://www.manageengine.com/patch-management/service-packs.html For more information, please visit here In case of queries or technical assistance contact support. Regards, Team ManageEngine
Unauthenticated Remote Code Execution Vulnerability has been fixed!
Hello everyone, Fix for the Remote Code Execution vulnerability in Device Control Plus has been released in the build 100356. This hotfix is available at https://www.manageengine.com/device-control/service-packs.html For more information, refer this link. In case of queries or for technical assistance please contact support. Best Regards, Team ManageEngine
Security Update | ManageEngine Application Control Plus
Hello Everyone, Fix for the Remote Code Execution vulnerability in Application Control Plus has been released in the build 100504. This hotfix is available at https://www.manageengine.com/application-control/service-packs.html For more information, please visit here. In case of queries or technical assistance contact support Regards, Team ManageEngine
Unauthenticated remote code execution vulnerability fixed
Hello Everyone, Fix for the Remote Code Execution vulnerability in Vulnerability Manager Plus has been released in the build 100346 This hotfix is available at https://www.manageengine.com/vulnerability-management/service-packs.html For more information, please visit here In case of queries or technical assistance contact support Regards, Team ManageEngine
Fix for Security Issue in Mobile Device Manager Plus MSP
Mobile Device Manager Plus MSP has fixed an arbitrary file upload vulnerability which would have otherwise allowed users with malicious intent to upload any file without validation using the log upload functionality. The security fix is available in build #92684 and above. You can download the latest build from here. For any queries or assistance, please reach to our support team at msp-mdm-support@manageengine.com. Follow #mdm-security for all security related updates in Mobile Device Manager Plus
Fix for Security Issue in Mobile Device Manager Plus
Mobile Device Manager Plus has fixed an arbitrary file upload vulnerability which would have otherwise allowed users with malicious intent to upload any file without validation using the log upload functionality. The security fix is available in build #92684 and above. You can download the latest build from here. For any queries or assistance, please reach to our support team at mdm-support@manageengine.com. Follow #mdm-security for all security related updates in Mobile Device Manager Plus
Desktop Central is still desperately lacking in patch/configuration job targeting...
This has been an issue for a good number of years now and, whilst DC appear to have made some changes (and even some improvements) to the way in which you are able to target jobs, there are still some pretty serious limitations and even some down-right failures in the way in which job targeting is handled. Here are a couple of posts, over at least the last six years, of examples where very specific requests for improvement have been made, with repeated "looking into it" and other non-committal responses:
Security Update - ManageEngine Desktop Central (Remote Code Execution - Fixed)
Hello Everyone, The remote code execution vulnerability in Desktop Central (CVE-2020-10189) has been fixed in build 10.0.479. The new hotfix is available at https://www.manageengine.com/products/desktop-central/service-packs.html For more information about the vulnerability, please visit https://www.manageengine.com/products/desktop-central/remote-code-execution-vulnerability.html Please contact support for any clarification or the assistance. Thank you.
Zero-Day Vulnerability - Desktop Central - March 6th, 2020
Is there any information regarding the zero-day vulnerability for Desktop Central that was announced today via the article: https://www.zdnet.com/article/zoho-zero-day-published-on-twitter/ ? Any guidance yet?
Tomcat Vulnerability?
Good morning, is the OPManager software vulnerable to the Tomcat exploit in the link below? https://www.cisecurity.org/advisory/a-vulnerability-in-apache-tomcat-could-allow-for-arbitrary-file-reading-cve-2020-1938_2020-028/
Are any ManageEngine products (like ServicedeskPlus) vulnerable to recent "Ghostcat" exploit?
i see referenced in this previous post https://pitstop.manageengine.com/portal/community/topic/java-standalone-application-any-servler-container-like-apache-tomcat-behind that some manageengine products are based on Apache Tomcat. given the most recent "ghostcat" exploit that was discovered, what is the eta for updates to use a version of tomcat which has this patched? Exploit details: https://www.cisecurity.org/advisory/a-vulnerability-in-apache-tomcat-could-allow-for-arbitrary-file-reading-cve-2020-1938_2020-028/
Self-signed SSL Certificate
Good Day If we want to access ServiceDesk Plus via our intranet we get the "Connection to this site is not secure" warning. Therefore, we tried to install a self-signed SSL-certificate. Whilst importing the certificate ServiceDesk Plus throws an error. In the Support-File we found the error "Exception occurred when importing the SSL certificate! : Self signed certificate cannot be imported from UI|". Is there any other way to import the certificate or to get rid of the warning?
Announcement on Ghostcat vulnerability (CVE-2020-1938)
Dear users, Ghostcat is a serious vulnerability in Apache Tomcat discovered by security researcher of Chaitin Tech. Due to a flaw in the Tomcat AJP protocol, an attacker can read or include any files in the webapp directories of Tomcat. For example, an attacker can read the webapp configuration files or source code. In addition, if the target web application has a file upload function, the attacker may execute malicious code on the target host by exploiting file inclusion through Ghostcat vulnerability.
REST API access to create and reply to email converstations
Hello all. Does anyone know if there is an exposed API to view, create and reply to email conversations in a ticket? I can see that there is a well-documneted API for Notes, but I am not able to find anything about Emails. Regards, Alex
SDP 11.1 / site change by user mail
Hi Can I automatically change the site by mail domain for new users? ex: if a@name.com then the site is "NAME"
Large File Attachment Notification to Requester
When a requester submits a ticket with a file attachment larger than 10 MB, the technicians receives a notification that the attachment was dropped. Can we also create a notification that gets sent to the requester when the attachment is dropped due to file size? Thanks
Monitoring Cisco Telepresence
Hello, I am trying to start monitoring Cisco TelePresence systems. I can see even, that if proper SNMP community string is provided, OpM discover the device out of the box. However - it is monitoring the device with availability only. My question is - did anyone succeeded in more detailed monitoring? like monitoring network interfaces (and its details, like drops etc.). Final scenario is monitor somehow "User Experience" - to be aware before bigger (more massive) issue comes. I would like to know
Form Rules on emailed Incidents
Can Field and Form rules run off of Incidents that are mailed in? We're trying to set it up so incidents that are emailed in with a certain subject and sender are sent to the proper group with the correct category set. But the variations of field rules I've tried don't seem to do anything at all on incidents that are emailed in. That's why I'd like to know if they can even run on emailed in request or if they can only run on request made while in ServiceDesk.
[Community Digest] ServiceDesk Plus - February 2020
A lot happens in a month on PitStop around ServiceDesk Plus. And, it's quite likely for you to have missed out on something interesting. So, we decided to bring you all the action of the last month in a digest. Read on and stay updated on all that's making PitStop the most happening IT hub. User Education and Resources: User Education opened to help you use ServiceDesk Plus to its fullest potential, https://www.youtube.com/watch?reload=9&v=EHsZASYhyKU&feature=youtu.be Resources: https://pitstop.manageengine.com/portal/community/topic/one-hundred-ways-to-make-servicedesk-plus-work-for-you-20-2-2020
[SDF-47403] Change Templates - Pre-populated Tasks
Is there a way to configure pre-populated tasks for your change template? Much like you can do in the Request Template under the request workflow? We have recurring system changes to document but do not want to re-create the same tasks everytime the change is created.
postgres data export help needed
I need to bulk export requests with all the data which must include all the conversation history. I have looked through custom reports and analytics plus but i cant find the table/ field where i can grab this from. Our ME database is postgres. Thanks
Service Desk Plus MSSQL query Last Update Time
I'm wanting to see if I can get some help with a SQL query that can add a column showing the number of days since the request was updated. I found the following query below from the forums that filters the database by records. but cant seem to figure out how to make a calculated field that shows the number of days since update. Any help you can give would be greatly appreciated. Thanks Tony Blandin SELECT ti.FIRST_NAME "Technician", wo.WORKORDERID "Request ID", aau.FIRST_NAME "Requester", cd.CATEGORYNAME
Critical PPP Daemon vulnerability opens up Linux systems to RCE attacks
Hello guys, The US-CERT has issued an advisory warning users of the new remote code execution (RCE) vulnerability CVE-2020-8597, affecting the PPPD (Point-to-Point Protocol Daemon) installed in almost all flavors of Linux based systems. Other than Linux systems, this vulnerability also affects few other networking applications and devices such as Cisco CallManager, TP-Link products, Synology, and OpenWRT Embedded OS. The vulnerability The vulnerability CVE-2020-8597 exists due to an error in
Critical PPP Daemon vulnerability opens up Linux systems to RCE attacks
Hello guys, The US-CERT has issued an advisory warning users of the new remote code execution (RCE) vulnerability CVE-2020-8597, affecting the PPPD (Point-to-Point Protocol Daemon) installed in almost all flavors of Linux based systems. Other than Linux systems, this vulnerability also affects few other networking applications and devices such as Cisco CallManager, TP-Link products, Synology, and OpenWRT Embedded OS. The vulnerability The vulnerability CVE-2020-8597 exists due to an error in
Incident Template
We receive automated emails into ServiceDesk Plus from a system which are logged as incidents using a specific template. However, the requester is set to the senders email address and we would like to change this to another requester automatically. Can Service Desk Plus do this? If so, how?
Critical PPP Daemon vulnerability opens up Linux systems to RCE attacks
Hello guys, The US-CERT has issued an advisory warning users of the new remote code execution (RCE) vulnerability CVE-2020-8597, affecting the PPPD (Point-to-Point Protocol Daemon) installed in almost all flavors of Linux based systems. Other than Linux systems, this vulnerability also affects few other networking applications and devices such as Cisco CallManager, TP-Link products, Synology, and OpenWRT Embedded OS. The vulnerability The vulnerability CVE-2020-8597 exists due to an error in
[SDF-24799] Templates for Announcements
Hello, I was wondering if Announcement Templates are on the road map for future releases? Our organization likes to have multiple templates for outages and notifications for the general business. Thanks!
Mandating a Field for Announcements
Hello, I was wondering if its possible to have a few specific fields mandated when users create announcements? I know its possible for templates but I can't seem to find it anywhere for announcements. For example, I would like to make "Announcement Type" field required before an announcement is created. Thanks!
Site Usage
Our organization is a City with many physical locations throughout our municipality. Before we ever started using ServiceDesk we had already called each one of these locations Sites. This caused some confusion early on as we started setting ServiceDesk up and unfortunately was never fixed. By ServiceDesk’s definition we should only have one Site, our City name. But as things are each actual location we have is listed under Sites. After time we made a change to what data is found in the Office field
How to audit OneDrive for Business activities
OneDrive for Business is widely used to store and retrieve documents. Since, these documents can be easily accessed, modified or deleted by any users who have access, you must keep track of all the actions performed in organization’s OneDrive for Business account and the person responsible for every action. Why use O365 Manager Plus to audit your OneDrive for Business? Native Office 365 auditing options such as PowerShell scripts and Office 365 Security & Compliance Center are either complex to use
Need help with a query report
Hi, I need a query report for the usage of a metered software. But I need the report ignoring the file version and the computer. It should be like this: User Name | Rule Name | Usage Duration user xy acad.exe 7 day, 5 hours, 30 min The normal Users with metered software splits the time according to the Product Version (file version) Maybe someone can help me with creating a query report. Thx bye, Alf
Next Page