Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HZohocorp Manageengine Adselfservice Plus
APPZohocorp6.1< 6.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
CVE-2021-40539CRITICAL9.8⚠ KEVPL ✓same product
Zoho ManageEngine ADSelfService Plus — Auth Bypass i RCE przez REST API
CVE-2025-11250CRITICAL9.1PL ✓same product
Authentication Bypass w Zohocorp ManageEngine ADSelfService Plus
CVE-2022-36413CRITICAL9.1PL ✓same product
Zoho ManageEngine ADSelfService Plus — brute-force umożliwia reset hasła
CVE-2021-37423CRITICAL9.8PL ✓same product
Przejęcie połączonych aplikacji w Zoho ManageEngine ADSelfService Plus