Improper Authentication in Zoho ManageEngine ADSelfService Plus - #VU27965

 

Improper Authentication in Zoho ManageEngine ADSelfService Plus - #VU27965

Published: May 18, 2020


Vulnerability identifier: #VU27965
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authentication process.

The vulnerability exists due to an error, which allowed a user to enable integration with other supported ManageEngine products bypassing authentication.


Affected software

Zoho ManageEngine ADSelfService Plus
Zoho ManageEngine EventLog Analyzer

Remediation

Install updates from vendor's website.

Zoho ManageEngine ADSelfService Plus - update to 5817
Zoho ManageEngine EventLog Analyzer - update to 12136

External References

Related Security Bulletins