Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
The vulnerability results from improper configuration of authentication filters (CWE-290 — Authentication Bypass by Spoofing). Incorrectly configured filters allow an attacker to bypass access controls and impersonate an authenticated user or administrator. The attack can be conducted remotely, over the network, without the need to possess an account or user interaction.
An attacker can gain unauthorized access to the system with a high level of privileges, resulting in a breach of confidentiality and integrity of data managed by the application, including potentially authentication credentials of Active Directory users.
ManageEngine ADSelfService Plus must be immediately updated to version 6519 or later. Details are available in the official manufacturer's bulletin: https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-11250.html
Zohocorp ManageEngine ADSelfService Plus in versions earlier than 6519
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NZohocorp Manageengine Adselfservice Plus
APPZohocorp6.5< 6.5
Related vulnerabilities
RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec
Zoho ManageEngine ADSelfService Plus — Auth Bypass i RCE przez REST API
Authentication bypass w Zoho ManageEngine ADSelfService Plus — kradzież tokenu sesji kontrolera domeny
Zoho ManageEngine ADSelfService Plus — brute-force umożliwia reset hasła
Przejęcie połączonych aplikacji w Zoho ManageEngine ADSelfService Plus