CVE-2022-36412: Critical severity manageengine supportcenter plus vulnerability
Published Jul 26, 2022
·Updated
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
Affected Software
3 affected components
ZohoCorp Manageengine Supportcenter Plus=11.0-11020
ZohoCorp Manageengine Supportcenter Plus=11.0-11021
ZohoCorp Manageengine Supportcenter Plus=11.0-11022
Event History
Jul 26, 2022
CVE Published
via MITRE·01:34 PM
Data Sourced
via MITRE·01:34 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-36412.
2
What is the severity of CVE-2022-36412?
The severity of CVE-2022-36412 is critical (9.8).
3
Which software versions are affected by CVE-2022-36412?
Zoho ManageEngine SupportCenter Plus versions 11.0-11020, 11.0-11021, and 11.0-11022 are affected by CVE-2022-36412.
4
What is the vulnerability description of CVE-2022-36412?
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass, allowing an API request to be executed with the credentials of a past authenticated user.
5
How can I fix CVE-2022-36412?
To fix CVE-2022-36412, it is recommended to update Zoho ManageEngine SupportCenter Plus to version 11.0-11023 or later.