First published: Fri Aug 04 2023(Updated: )
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADManager Plus | <7.2 | |
Zohocorp ManageEngine ADManager Plus | =7.2-7200 | |
Zohocorp ManageEngine ADManager Plus | =7.2-7201 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38332 is medium with a CVSS score of 6.5.
CVE-2023-38332 affects Zoho ManageEngine ADManager Plus versions up to 7.2-7201.
Authenticated users can take over another user's account through sensitive information disclosure caused by CVE-2023-38332.
To fix CVE-2023-38332, it is recommended to update Zoho ManageEngine ADManager Plus to version 7.2-7202 or later.
You can find more information about CVE-2023-38332 on the Zoho ManageEngine website.