CVE-2023-38332: Medium severity zoho corporation admanager plus vulnerability
Published Aug 4, 2023
·Updated
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
Affected Software
3 affected components
ZohoCorp ManageEngine ADManager Plus<7.2
ZohoCorp ManageEngine ADManager Plus=7.2-7200
ZohoCorp ManageEngine ADManager Plus=7.2-7201
Event History
Aug 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
06:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-38332?
The severity of CVE-2023-38332 is medium with a CVSS score of 6.5.
2
How does CVE-2023-38332 affect Zoho ManageEngine ADManager Plus?
CVE-2023-38332 affects Zoho ManageEngine ADManager Plus versions up to 7.2-7201.
3
What can authenticated users do with CVE-2023-38332?
Authenticated users can take over another user's account through sensitive information disclosure caused by CVE-2023-38332.
4
How can I fix CVE-2023-38332?
To fix CVE-2023-38332, it is recommended to update Zoho ManageEngine ADManager Plus to version 7.2-7202 or later.
5
Where can I find more information about CVE-2023-38332?
You can find more information about CVE-2023-38332 on the Zoho ManageEngine website.