SB2022052502 - Multiple vulnerabilities in Zoho ManageEngine ADSelfService Plus



SB2022052502 - Multiple vulnerabilities in Zoho ManageEngine ADSelfService Plus

Published: May 25, 2022

Security Bulletin ID SB2022052502
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Man-in-the-Middle (MitM) attack (CVE-ID: CVE-2021-37423)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insecure communication during password synchronization. A remote unauthenticated attacker can delete the real Password Sync Agent from the database and register a fake Password Sync Agent, breaching the sync agent functionality.


2) Information disclosure (CVE-ID: N/A)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the username information in the request URL is sent to the ADSelfService Plus server upon successful IdP authentication. A remote attacker can obtain this information in certain cases.


Remediation

Install update from vendor's website.