First published: Tue Sep 26 2023(Updated: )
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zohocorp ManageEngine ADManager Plus | <7.2 | |
Zohocorp ManageEngine ADManager Plus | =7.2-7200 | |
Zohocorp ManageEngine ADManager Plus | =7.2-7201 | |
Zohocorp ManageEngine ADManager Plus | =7.2-7202 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41904 is medium.
CVE-2023-41904 allows 2FA bypass (for AuthToken generation) in REST APIs of Zoho ManageEngine ADManager Plus.
Zoho ManageEngine ADManager Plus versions up to 7.2-7202 are affected by CVE-2023-41904.
A fix for CVE-2023-41904 may be available in a future update of Zoho ManageEngine ADManager Plus. Please refer to the official documentation or contact Zoho support for further information.
The CWE ID for CVE-2023-41904 is CWE-287 (Improper Authentication).