First published: Thu Feb 17 2011(Updated: )
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accounts/ValidateUser, and then providing a new password to accounts/ResetResult.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus | <=4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3273 has a high severity rating due to its ability to allow unauthorized password resets.
To mitigate CVE-2010-3273, upgrade to ManageEngine ADSelfService Plus version 4.5 Build 4500 or later.
CVE-2010-3273 enables remote attackers to perform unauthorized password resets on user accounts.
CVE-2010-3273 affects ManageEngine ADSelfService Plus versions prior to 4.5 Build 4500.
CVE-2010-3273 can lead to unauthorized access to arbitrary user accounts.