CVE-2021-37421: Critical severity ZohoCorp ManageEngine ADSelfService Plus vulnerability
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-37421?
CVE-2021-37421 is a vulnerability in Zoho ManageEngine ADSelfService Plus 6103 and prior that allows bypassing of admin portal access restrictions.
How severe is CVE-2021-37421?
CVE-2021-37421 has a severity rating of 9.8 (critical).
Which software versions are affected by CVE-2021-37421?
Zoho ManageEngine ADSelfService Plus versions 6.1 up to 6.1-6103 are affected by CVE-2021-37421.
How can I fix CVE-2021-37421?
Upgrade Zoho ManageEngine ADSelfService Plus to version 6.1-6104 which includes important security fixes.
Where can I find more information about CVE-2021-37421?
You can refer to the following references for more information: - [https://blog.stmcyber.com/vulns/cve-2021-37421/](https://blog.stmcyber.com/vulns/cve-2021-37421/) - [https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes](https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes)