ZDI-CAN-20008: ZDI-23-437: ManageEngine ADSelfService Plus DomainUserSSPLogonAuth Improper Input Validation Denial-of-Service Vulnerability
Published Apr 12, 2023
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ManageEngine ADSelfService Plus. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
ManageEngine ADSelfService Plus
Event History
Apr 12, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20008?
The severity of ZDI-CAN-20008 is high due to its ability to cause a denial-of-service condition without authentication.
2
How do I fix ZDI-CAN-20008?
To fix ZDI-CAN-20008, apply the latest security patch provided by ManageEngine for ADSelfService Plus.
3
Can ZDI-CAN-20008 be exploited remotely?
Yes, ZDI-CAN-20008 can be exploited remotely without requiring authentication.
4
What software is affected by ZDI-CAN-20008?
ZDI-CAN-20008 affects ManageEngine ADSelfService Plus installations.
5
What type of vulnerability is ZDI-CAN-20008?
ZDI-CAN-20008 is a denial-of-service vulnerability.