Improper Authentication in Zoho ManageEngine ADSelfService Plus - #VU27965
Published: May 18, 2020
Vulnerability identifier: #VU27965
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to an error, which allowed a user to enable integration with other supported ManageEngine products bypassing authentication.
Affected software
Zoho ManageEngine ADSelfService Plus
Zoho ManageEngine EventLog Analyzer
Zoho ManageEngine EventLog Analyzer
Remediation
Install updates from vendor's website.
Zoho ManageEngine ADSelfService Plus - update to 5817
Zoho ManageEngine EventLog Analyzer - update to 12136
Zoho ManageEngine EventLog Analyzer - update to 12136