CRITICAL🇵🇱 Wersja polska

CVE-2023-35854

CVSS 9.8v3.1pub. 2023-06-20upd. 2024-11-21

Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Zohocorp Manageengine Adselfservice Plus

    APP
    Zohocorp
    6.1< 6.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product

RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec

CVE-2021-40539CRITICAL9.8⚠ KEVPL ✓same product

Zoho ManageEngine ADSelfService Plus — Auth Bypass i RCE przez REST API

CVE-2025-11250CRITICAL9.1PL ✓same product

Authentication Bypass w Zohocorp ManageEngine ADSelfService Plus

CVE-2022-36413CRITICAL9.1PL ✓same product

Zoho ManageEngine ADSelfService Plus — brute-force umożliwia reset hasła

CVE-2021-37423CRITICAL9.8PL ✓same product

Przejęcie połączonych aplikacji w Zoho ManageEngine ADSelfService Plus