Zohocorp

Manageengine Adselfservice Plus

54 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 1.24%
  • Veröffentlicht 23.06.2026 09:16:28
  • Zuletzt bearbeitet 24.06.2026 17:16:56

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

  • EPSS 1.7%
  • Veröffentlicht 21.05.2026 12:36:17
  • Zuletzt bearbeitet 21.05.2026 15:26:35

Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.

  • EPSS 7.87%
  • Veröffentlicht 23.02.2026 06:54:25
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.

  • EPSS 1.42%
  • Veröffentlicht 13.01.2026 13:35:18
  • Zuletzt bearbeitet 29.01.2026 19:12:29

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

  • EPSS 27.77%
  • Veröffentlicht 14.05.2025 11:00:27
  • Zuletzt bearbeitet 30.09.2025 15:05:27

Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.

  • EPSS 1.43%
  • Veröffentlicht 03.03.2025 08:15:15
  • Zuletzt bearbeitet 30.09.2025 15:01:26

Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

  • EPSS 2.27%
  • Veröffentlicht 27.05.2024 18:15:09
  • Zuletzt bearbeitet 27.11.2024 16:25:10

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

  • EPSS 7.81%
  • Veröffentlicht 11.01.2024 08:15:35
  • Zuletzt bearbeitet 21.11.2024 08:46:09

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 15.11.2023 21:15:08
  • Zuletzt bearbeitet 13.02.2025 18:16:03

An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use t...

  • EPSS 20.19%
  • Veröffentlicht 06.09.2023 05:15:42
  • Zuletzt bearbeitet 21.11.2024 08:08:34

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine...