Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZohocorp Manageengine Adselfservice Plus
APPZohocorp6.1< 6.1
CISA KEV — detailsi
- Vendori
- Zoho ↗
- Producti
- ManageEngine
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- November 17, 2021(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Required action (CISA)i
Apply updates per vendor instructions.
CISA descriptioni
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARE⏰CISA DEADLINE: 17 listopada 2021
Tags
RCEAuth Bypass
References
Related vulnerabilities
CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
CVE-2025-11250CRITICAL9.1PL ✓same product
Authentication Bypass w Zohocorp ManageEngine ADSelfService Plus
CVE-2023-35854CRITICAL9.8PL ✓same product
Authentication bypass w Zoho ManageEngine ADSelfService Plus — kradzież tokenu sesji kontrolera domeny
CVE-2022-36413CRITICAL9.1PL ✓same product
Zoho ManageEngine ADSelfService Plus — brute-force umożliwia reset hasła
CVE-2021-37423CRITICAL9.8PL ✓same product
Przejęcie połączonych aplikacji w Zoho ManageEngine ADSelfService Plus