QID 375840
Date Published: 2021-09-09
QID 375840: Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
ManageEngine ADSelfService Plus is a secure, web-based, end-user password reset management and single sign-on solution that helps domain users to perform self-service password reset, self-service account unlock, employee self-update of personal details (e.g., mobile numbers and photos) in Microsoft Windows Active Directory.
Zoho ManageEngine ADSelfService Plus has Authentication Bypass Vulnerability
Affected Version:
Zoho ManageEngineADSelfService Plus upto build 6113
QID Detection Logic (Authenticated):
Checks for vulnerable version of ManageEngine ADSelfService Plus upto build 6113
This vulnerability allows an attacker to gain unauthorized access to the product through REST API endpoints by sending a specially crafted request. This would allow the attacker to carry out subsequent attacks resulting in RCE.
Customers are advised to visit release-notes for updates pertaining this vulnerability.
CVEs related to QID 375840
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ADSelfService Plus |
|