First published: Tue Jul 26 2022(Updated: )
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Supportcenter Plus | =11.0-11020 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11021 | |
Zohocorp Manageengine Supportcenter Plus | =11.0-11022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-36412.
The severity of CVE-2022-36412 is critical (9.8).
Zoho ManageEngine SupportCenter Plus versions 11.0-11020, 11.0-11021, and 11.0-11022 are affected by CVE-2022-36412.
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass, allowing an API request to be executed with the credentials of a past authenticated user.
To fix CVE-2022-36412, it is recommended to update Zoho ManageEngine SupportCenter Plus to version 11.0-11023 or later.