CVE-2023-41904: Medium severity zoho corporation admanager plus vulnerability
Published Sep 26, 2023
·Updated
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
Affected Software
4 affected components
ZohoCorp ManageEngine ADManager Plus<7.2
ZohoCorp ManageEngine ADManager Plus=7.2-7200
ZohoCorp ManageEngine ADManager Plus=7.2-7201
ZohoCorp ManageEngine ADManager Plus=7.2-7202
Event History
Sep 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-41904?
The severity of CVE-2023-41904 is medium.
2
How does CVE-2023-41904 affect Zoho ManageEngine ADManager Plus?
CVE-2023-41904 allows 2FA bypass (for AuthToken generation) in REST APIs of Zoho ManageEngine ADManager Plus.
3
Which versions of Zoho ManageEngine ADManager Plus are affected by CVE-2023-41904?
Zoho ManageEngine ADManager Plus versions up to 7.2-7202 are affected by CVE-2023-41904.
4
How can I fix CVE-2023-41904?
A fix for CVE-2023-41904 may be available in a future update of Zoho ManageEngine ADManager Plus. Please refer to the official documentation or contact Zoho support for further information.
5
What is the CWE ID for CVE-2023-41904?
The CWE ID for CVE-2023-41904 is CWE-287 (Improper Authentication).