First published: Mon Aug 30 2021(Updated: )
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Adselfservice Plus | <6.1 | |
Zohocorp Manageengine Adselfservice Plus | =6.1 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6100 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6101 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6102 | |
Zohocorp Manageengine Adselfservice Plus | =6.1-6103 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37421 is a vulnerability in Zoho ManageEngine ADSelfService Plus 6103 and prior that allows bypassing of admin portal access restrictions.
CVE-2021-37421 has a severity rating of 9.8 (critical).
Zoho ManageEngine ADSelfService Plus versions 6.1 up to 6.1-6103 are affected by CVE-2021-37421.
Upgrade Zoho ManageEngine ADSelfService Plus to version 6.1-6104 which includes important security fixes.
You can refer to the following references for more information: - [https://blog.stmcyber.com/vulns/cve-2021-37421/](https://blog.stmcyber.com/vulns/cve-2021-37421/) - [https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes](https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes)