9.1
CVE-2025-11250
- EPSS 1.44%
- Veröffentlicht 13.01.2026 13:35:18
- Zuletzt bearbeitet 29.01.2026 19:12:29
- Erkennungen
Authentication Bypass
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Adselfservice Plus Version < 6.5
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6500
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6501
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6502
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6503
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6504
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6505
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6506
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6507
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6508
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6509
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6510
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6511
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6512
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6513
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6514
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6515
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6516
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6517
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6518
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.44% | 0.709 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 0fc0942c-577d-436f-ae8e-945763c79b02 | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-11250.html