First published: Mon Jul 04 2022(Updated: )
Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Adselfservice Plus | <6.2 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6200 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6201 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6202 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34829 has a severity rating of 7.5 (high).
CVE-2022-34829 affects Zoho ManageEngine ADSelfService Plus versions up to and including 6.2-6202.
A denial of service attack can be performed using a crafted payload to the Mobile App Deployment API in Zoho ManageEngine ADSelfService Plus before version 6203.
Yes, the fix for CVE-2022-34829 is available in version 6.2-6203 of Zoho ManageEngine ADSelfService Plus.
More information about CVE-2022-34829 can be found in the advisory located at: https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-34829.html