First published: Thu Jan 11 2024(Updated: )
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
Credit: 0fc0942c-577d-436f-ae8e-945763c79b02
Affected Software | Affected Version | How to fix |
---|---|---|
ADSelfService Plus | <6.4 | |
ADSelfService Plus | =6.4-6400 | |
ADSelfService Plus | =6.4-6401 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0252 has a high severity rating due to its potential for remote code execution.
To fix CVE-2024-0252, upgrade ManageEngine ADSelfService Plus to the latest version above 6.4.
CVE-2024-0252 affects the load balancer component of ManageEngine ADSelfService Plus versions 6401 and below.
Yes, authentication is required to exploit CVE-2024-0252.
ManageEngine ADSelfService Plus versions 6400 and 6401 are impacted by CVE-2024-0252.