QID 378406
Date Published: 2023-08-10
QID 378406: Zoho ManageEngine ADSelfService Plus denial of Service (DoS) Vulnerability
ManageEngine ADSelfService Plus is a secure, web-based, end-user password reset management and single sign-on solution that helps domain users to perform self-service password reset, self-service account unlock, employee self-update of personal details (e.g., mobile numbers and photos) in Microsoft Windows Active Directory.
CVE-2022-34829 refers to a denial-of-service (DoS) attack security vulnerability reported in ManageEngine ADSelfService Plus that caused the application to restart whenever a call with a vulnerable payload was sent to the Mobile App Deployment API.
Affected Version:
Zoho ManageEngine ADSelfService Plus build 6202 and below
QID Detection Logic:
Authenticated : Checks for vulnerable version of ManageEngine ADSelfService Plus build 6202 and below
Successful exploitation of this vulnerability will cause the application to restart every time the Mobile App Deployment API receives a vulnerable payload.
Customers are advised to visit Zoho ManageEngine ADSelfService Plus Security Advisory for updates pertaining this vulnerability.
- Zoho ManageEngine ADSelfService Plus Security Advisory -
www.manageengine.com/products/self-service-password/advisory/CVE-2022-34829.html
CVEs related to QID 378406
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Zoho ManageEngine ADSelfService Plus Security Advisory |
|