CVE-2022-28987: Medium severity adselfservice plus vulnerability
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28987?
The severity of CVE-2022-28987 is medium with a severity value of 5.3.
How does CVE-2022-28987 affect Zoho ManageEngine ADSelfService Plus?
CVE-2022-28987 allows attackers to perform username enumeration in Zoho ManageEngine ADSelfService Plus.
How can an attacker exploit CVE-2022-28987?
An attacker can exploit CVE-2022-28987 by sending a crafted POST request to /ServletAPI/accounts/login.
Is there a fix available for CVE-2022-28987?
Yes, a fix is available for CVE-2022-28987. It is recommended to update to Zoho ManageEngine ADSelfService Plus version 6.2.0.2.
Where can I find more information about CVE-2022-28987?
More information about CVE-2022-28987 can be found at the following references: [Reference 1](https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/adselfservice-userenum.md), [Reference 2](https://github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/adselfservice-userenum.py), [Reference 3](https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-28987.html).