CVE-2022-34829: High severity adselfservice plus vulnerability
Published Jul 4, 2022
·Updated
Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.
Affected Software
4 affected components
ZohoCorp ManageEngine ADSelfService Plus<6.2
ZohoCorp ManageEngine ADSelfService Plus=6.2-6200
ZohoCorp ManageEngine ADSelfService Plus=6.2-6201
ZohoCorp ManageEngine ADSelfService Plus=6.2-6202
Remediation
Event History
Jul 4, 2022
CVE Published
via MITRE·07:25 PM
Data Sourced
via MITRE·07:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34829?
CVE-2022-34829 has a severity rating of 7.5 (high).
2
How does CVE-2022-34829 affect Zoho ManageEngine ADSelfService Plus?
CVE-2022-34829 affects Zoho ManageEngine ADSelfService Plus versions up to and including 6.2-6202.
3
How can a denial of service attack be performed using CVE-2022-34829?
A denial of service attack can be performed using a crafted payload to the Mobile App Deployment API in Zoho ManageEngine ADSelfService Plus before version 6203.
4
Is there a fix available for CVE-2022-34829?
Yes, the fix for CVE-2022-34829 is available in version 6.2-6203 of Zoho ManageEngine ADSelfService Plus.
5
Where can I find more information about CVE-2022-34829?
More information about CVE-2022-34829 can be found in the advisory located at: https://www.manageengine.com/products/self-service-password/advisory/CVE-2022-34829.html