Critical severity9.8NVD Advisory· Published Jul 26, 2022· Updated Jun 17, 2026
CVE-2022-36412
CVE-2022-36412
Description
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11020:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11020:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11021:*:*:*:*:*:*
- cpe:2.3:a:zohocorp:manageengine_supportcenter_plus:11.0:11022:*:*:*:*:*:*
- Zoho/ManageEngine SupportCenter Plusdescription
- Range: <11023
Patches
Vulnerability mechanics
References
1- www.manageengine.com/products/support-center/cve-2022-36412.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.