ADSelfService Plus
by Manageengine
CVEs (29)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40539 | Cri | 0.93 | 9.8 | 0.99 | KEV | Sep 7, 2021 | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | |
| CVE-2021-28958 | Cri | 0.70 | 9.8 | 0.73 | Jun 25, 2021 | Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. | ||
| CVE-2018-5353 | Cri | 0.65 | 9.8 | 0.11 | Sep 30, 2020 | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable… | ||
| CVE-2019-3905 | Cri | 0.65 | 10.0 | 0.03 | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. | ||
| CVE-2023-35854 | Cri | 0.64 | 9.8 | 0.06 | Jun 20, 2023 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is… | ||
| CVE-2021-37424 | Cri | 0.64 | 9.8 | 0.05 | Sep 21, 2021 | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. | ||
| CVE-2021-37422 | Cri | 0.64 | 9.8 | 0.03 | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. | ||
| CVE-2021-37423 | Cri | 0.64 | 9.8 | 0.03 | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. | ||
| CVE-2021-33256 | Hig | 0.64 | 8.8 | 0.79 | Aug 9, 2021 | A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User… | ||
| CVE-2020-11552 | Cri | 0.64 | 9.8 | 0.07 | Aug 11, 2020 | An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a… | ||
| CVE-2022-29457 | Hig | 0.61 | 8.8 | 0.08 | Apr 18, 2022 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. | ||
| CVE-2026-11374 | Cri | 0.59 | 9.0 | 0.03 | Jun 23, 2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | ||
| CVE-2024-0252 | Hig | 0.58 | 8.8 | 0.08 | Jan 11, 2024 | ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability. | ||
| CVE-2026-2740 | Hig | 0.55 | 8.4 | 0.04 | May 21, 2026 | Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency. | ||
| CVE-2025-3833 | Hig | 0.55 | 8.1 | 0.45 | May 14, 2025 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | ||
| CVE-2025-1723 | Hig | 0.53 | 8.1 | 0.01 | Mar 3, 2025 | Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. | ||
| CVE-2022-34829 | Hig | 0.49 | 7.5 | 0.04 | Jul 4, 2022 | Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API. | ||
| CVE-2021-37419 | Hig | 0.49 | 7.5 | 0.02 | Sep 21, 2021 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. | ||
| CVE-2019-7161 | Hig | 0.49 | 7.5 | 0.06 | Mar 21, 2019 | An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data. | ||
| CVE-2023-35719 | Med | 0.46 | 6.8 | 0.25 | Sep 6, 2023 | ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.… |
- risk 0.93cvss 9.8epss 0.99
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
- risk 0.70cvss 9.8epss 0.73
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
- risk 0.65cvss 9.8epss 0.11
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable…
- risk 0.65cvss 10.0epss 0.03
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
- risk 0.64cvss 9.8epss 0.06
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is…
- risk 0.64cvss 9.8epss 0.05
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
- risk 0.64cvss 8.8epss 0.79
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User…
- risk 0.64cvss 9.8epss 0.07
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a…
- risk 0.61cvss 8.8epss 0.08
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
- risk 0.59cvss 9.0epss 0.03
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
- risk 0.58cvss 8.8epss 0.08
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
- risk 0.55cvss 8.4epss 0.04
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent machines due to the bug in the 3rd party dependency.
- risk 0.55cvss 8.1epss 0.45
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
- risk 0.53cvss 8.1epss 0.01
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
- risk 0.49cvss 7.5epss 0.04
Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.
- risk 0.49cvss 7.5epss 0.02
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
- risk 0.49cvss 7.5epss 0.06
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.
- risk 0.46cvss 6.8epss 0.25
ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of ManageEngine ADSelfService Plus.…
Page 1 of 2