Medium severity5.3NVD Advisory· Published May 20, 2022· Updated Jun 17, 2026
CVE-2022-28987
CVE-2022-28987
Description
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.1:6121:*:*:*:*:*:*
- Zoho/ManageEngine ADSelfService Plusdescription
- Range: <6202
Patches
Vulnerability mechanics
References
3- github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/adselfservice-userenum.mdnvdExploitThird Party Advisory
- github.com/passtheticket/vulnerability-research/blob/main/manage-engine-apps/adselfservice-userenum.pynvdExploitThird Party Advisory
- www.manageengine.com/products/self-service-password/advisory/CVE-2022-28987.htmlnvd
News mentions
0No linked articles in our index yet.