CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-11250

CVSS 9.1v3.1pub. 2026-01-13upd. 2026-01-29

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

🤖 AI Analysis
How it works

The vulnerability results from improper configuration of authentication filters (CWE-290 — Authentication Bypass by Spoofing). Incorrectly configured filters allow an attacker to bypass access controls and impersonate an authenticated user or administrator. The attack can be conducted remotely, over the network, without the need to possess an account or user interaction.

Impact

An attacker can gain unauthorized access to the system with a high level of privileges, resulting in a breach of confidentiality and integrity of data managed by the application, including potentially authentication credentials of Active Directory users.

Mitigation & patch

ManageEngine ADSelfService Plus must be immediately updated to version 6519 or later. Details are available in the official manufacturer's bulletin: https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-11250.html

Who is affected

Zohocorp ManageEngine ADSelfService Plus in versions earlier than 6519

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Zohocorp Manageengine Adselfservice Plus

    APP
    Zohocorp
    6.5< 6.5
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-47966CRITICAL9.8⚠ KEVPL ✓same product

RCE w wielu produktach Zoho ManageEngine przez podatną bibliotekę Apache Santuario xmlsec

CVE-2021-40539CRITICAL9.8⚠ KEVPL ✓same product

Zoho ManageEngine ADSelfService Plus — Auth Bypass i RCE przez REST API

CVE-2023-35854CRITICAL9.8PL ✓same product

Authentication bypass w Zoho ManageEngine ADSelfService Plus — kradzież tokenu sesji kontrolera domeny

CVE-2022-36413CRITICAL9.1PL ✓same product

Zoho ManageEngine ADSelfService Plus — brute-force umożliwia reset hasła

CVE-2021-37423CRITICAL9.8PL ✓same product

Przejęcie połączonych aplikacji w Zoho ManageEngine ADSelfService Plus