QID 378404
Date Published: 2023-04-20
QID 378404: Zoho ManageEngine ADSelfService Plus User Enumeration Vulnerability
ManageEngine ADSelfService Plus is a secure, web-based, end-user password reset management and single sign-on solution that helps domain users to perform self-service password reset, self-service account unlock, employee self-update of personal details (e.g., mobile numbers and photos) in Microsoft Windows Active Directory.
CVE-2022-28987 refers to a security vulnerability reported in ManageEngine ADSelfService Plus that allowed an attacker to identify existing valid users in the domain through user enumeration using product login API.
Affected Version:
Zoho ManageEngine ADSelfService Plus build 6201 and below
QID Detection Logic:
Authenticated : Checks for vulnerable version of ManageEngine ADSelfService Plus build 6201 and below
Successful exploitation of this vulnerability allows the attacker to identify valid users in the organization.
Customers are advised to visit Zoho ManageEngine ADSelfService Plus Security Advisory for updates pertaining this vulnerability.
- Zoho ManageEngine ADSelfService Plus Security Advisory -
www.manageengine.com/products/self-service-password/advisory/CVE-2022-28987.html
CVEs related to QID 378404
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine ADSelfService Plus Security Advisory |
|