QID 378366
Date Published: 2023-04-12
QID 378366: Zoho ManageEngine SupportCenter Plus Authentication Bypass Vulnerability
Zoho ManageEngine SupportCenter Plus is vulnerable to authentication bypass vulnerability.
This vulnerability allows an adversary to perform multiple operations using V3 APIs in SupportCenter Plus without the necessary credentials. The lack of a proper mechanism to flush out the previously authenticated users' credentials allows non-login users to perform V3 API operations.
Affected Versions:
SupportCenter Plus versions from 11022, 11021 and 11020
QID Detection Logic (Authenticated):
Windows: Checks for vulnerable version of ManageEngine SupportCenter Plus by reading the version from buildinfo.xml file.
Successful exploitation of this vulnerability allows an unauthenticated users to perform any V3 API operations as someone else.
Solution
Vendor has released patches addressing the vulnerability. For more information please refer to Zoho ManageEngine Security Advisory
Vendor References
- Zoho ManageEngine Security Advisory -
www.manageengine.com/products/support-center/cve-2022-36412.html
CVEs related to QID 378366
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine Security Advisory |
|