CVE-2022-36413: Critical severity adselfservice plus vulnerability
Published Mar 23, 2023
·Updated
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
Affected Software
19 affected components
ZohoCorp ManageEngine ADSelfService Plus<6.2
ZohoCorp ManageEngine ADSelfService Plus=6.2-6200
ZohoCorp ManageEngine ADSelfService Plus=6.2-6201
ZohoCorp ManageEngine ADSelfService Plus=6.2-6202
ZohoCorp ManageEngine ADSelfService Plus=6.2-6203
ZohoCorp ManageEngine ADSelfService Plus=6.2-6204
ZohoCorp ManageEngine ADSelfService Plus=6.2-6205
ZohoCorp ManageEngine ADSelfService Plus=6.2-6206
ZohoCorp ManageEngine ADSelfService Plus=6.2-6207
ZohoCorp ManageEngine ADSelfService Plus=6.2-6208
ZohoCorp ManageEngine ADSelfService Plus=6.2-6209
ZohoCorp ManageEngine ADSelfService Plus=6.2-6210
ZohoCorp ManageEngine ADSelfService Plus=6.2-6211
ZohoCorp ManageEngine ADSelfService Plus=6.2-6212
ZohoCorp ManageEngine ADSelfService Plus=6.2-6213
ZohoCorp ManageEngine ADSelfService Plus=6.2-6214
ZohoCorp ManageEngine ADSelfService Plus=6.2-6215
ZohoCorp ManageEngine ADSelfService Plus=6.2-6216
ZohoCorp ManageEngine ADSelfService Plus=6.2-6217
Remediation
Event History
Mar 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-36413.
2
What is the severity of CVE-2022-36413?
The severity of CVE-2022-36413 is critical with a CVSS score of 9.1.
3
What is affected by CVE-2022-36413?
Zoho ManageEngine ADSelfService Plus versions 6.2-6200 through 6.2-6203 are affected by CVE-2022-36413.
4
What is the impact of CVE-2022-36413?
CVE-2022-36413 can be exploited to perform a brute-force attack that leads to a password reset on IDM applications.
5
Is there a fix for CVE-2022-36413?
Yes, Zoho has released a patch to address the vulnerability. Please refer to the vendor's advisory for more information.