9.1

CVE-2025-11250

Authentication Bypass

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6500
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6501
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6502
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6503
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6504
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6505
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6506
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6507
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6508
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6509
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6510
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6511
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6512
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6513
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6514
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6515
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6516
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6517
Zohocorp ≫ Manageengine Adselfservice Plus Version 6.5 Update 6518
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.44% 0.709
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
0fc0942c-577d-436f-ae8e-945763c79b02 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-11250.html
Patch
Vendor Advisory