CVE-2021-37927: Critical severity ZohoCorp ManageEngine ADManager Plus vulnerability
Published Sep 22, 2021
·Updated
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
Affected Software
6 affected components
ZohoCorp ManageEngine ADManager Plus<7.1
ZohoCorp ManageEngine ADManager Plus=7.1
ZohoCorp ManageEngine ADManager Plus=7.1-7100
ZohoCorp ManageEngine ADManager Plus=7.1-7101
ZohoCorp ManageEngine ADManager Plus=7.1-7102
ZohoCorp ManageEngine ADManager Plus=7.1-7110
Event History
Sep 22, 2021
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-37927?
CVE-2021-37927 is a vulnerability in Zoho ManageEngine ADManager Plus version 7110 and prior that allows account takeover via SSO.
2
How severe is CVE-2021-37927?
CVE-2021-37927 has a severity rating of 9.8 (Critical).
3
Which software versions are affected by CVE-2021-37927?
Zoho ManageEngine ADManager Plus versions 7110 and prior are affected by CVE-2021-37927.
4
Is there a fix available for CVE-2021-37927?
Yes, the fix for CVE-2021-37927 is available in version 7.1-7111 of Zoho ManageEngine ADManager Plus.
5
Are there any additional references for CVE-2021-37927?
Yes, you can refer to the following links for more information: [1] ManageEngine website [2] Zoho ManageEngine ADManager Plus release notes [3] Zoho ManageEngine Self-Service Password release notes