First published: Thu Feb 17 2011(Updated: )
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus | <=4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-3272 is considered high due to its impact on user account security.
To fix CVE-2010-3272, upgrade ManageEngine ADSelfService Plus to version 4.5 Build 4500 or later.
CVE-2010-3272 enables remote attackers to reset user passwords and potentially gain unauthorized access to user accounts.
Versions of ManageEngine ADSelfService Plus prior to 4.5 Build 4500 are affected by CVE-2010-3272.
The primary vulnerability in CVE-2010-3272 lies in the insecure handling of security questions during the password reset process.