First published: Thu Mar 23 2023(Updated: )
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp Manageengine Adselfservice Plus | <6.2 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6200 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6201 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6202 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6203 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6204 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6205 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6206 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6207 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6208 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6209 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6210 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6211 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6212 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6213 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6214 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6215 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6216 | |
Zohocorp Manageengine Adselfservice Plus | =6.2-6217 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-36413.
The severity of CVE-2022-36413 is critical with a CVSS score of 9.1.
Zoho ManageEngine ADSelfService Plus versions 6.2-6200 through 6.2-6203 are affected by CVE-2022-36413.
CVE-2022-36413 can be exploited to perform a brute-force attack that leads to a password reset on IDM applications.
Yes, Zoho has released a patch to address the vulnerability. Please refer to the vendor's advisory for more information.