
CVE-2022-28810 – Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-28810
18 Apr 2022 — Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field. Zoho ManageEngine ADSelfService Plus ... • https://packetstorm.news/files/id/166816 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-798: Use of Hard-coded Credentials •

CVE-2022-24681
https://notcve.org/view.php?id=CVE-2022-24681
07 Apr 2022 — Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. Zoho ManageEngine ADSelfService Plus versiones anteriores a 6121, permite un ataque de tipo XSS por medio del atributo welcome name en la pantalla Reset Password, Unlock Account, o User Must Change Password • https://manageengine.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-20148
https://notcve.org/view.php?id=CVE-2021-20148
03 Jan 2022 — ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by authenticating to the service and then sending a request specifying the password policy file of the other domain. ManageEngine ADSelfService Plus versiones anteriores a la compilación 6116, almacena el ar... • https://www.tenable.com/security/research/tra-2021-52 • CWE-552: Files or Directories Accessible to External Parties •

CVE-2021-20147
https://notcve.org/view.php?id=CVE-2021-20147
03 Jan 2022 — ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists. ManageEngine ADSelfService Plus versiones anteriores a la compilación 6116, contiene una discrepancia de respuesta observable en la operación UMCP de la ChangePasswordAPI. Esto permite a un atacante remoto no autenticado determinar si se presenta un usuario de dominio de W... • https://www.tenable.com/security/research/tra-2021-52 • CWE-203: Observable Discrepancy •

CVE-2021-37422
https://notcve.org/view.php?id=CVE-2021-37422
10 Sep 2021 — Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, es vulnerable a una inyección SQL mientras se vinculan las bases de datos • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-37423
https://notcve.org/view.php?id=CVE-2021-37423
10 Sep 2021 — Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, son vulnerables a una toma de posesión de aplicaciones vinculadas • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release •

CVE-2021-40539 – Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2021-40539
07 Sep 2021 — Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. Zoho ManageEngine ADSelfService Plus versiones 6113 y anteriores, es vulnerable a una omisión de autenticación de la API REST con una ejecución de código remota resultante Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. • https://packetstorm.news/files/id/165085 • CWE-706: Use of Incorrectly-Resolved Name or Reference •

CVE-2021-37421
https://notcve.org/view.php?id=CVE-2021-37421
30 Aug 2021 — Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, son vulnerables a una evasión de la restricción de acceso al portal de administración. • https://blog.stmcyber.com/vulns/cve-2021-37421 • CWE-345: Insufficient Verification of Data Authenticity •

CVE-2021-37417
https://notcve.org/view.php?id=CVE-2021-37417
30 Aug 2021 — Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, permiten omitir el CAPTCHA debido a una comprobación inapropiada de los parámetros. • https://blog.stmcyber.com/vulns/cve-2021-37417 • CWE-287: Improper Authentication •

CVE-2021-37416
https://notcve.org/view.php?id=CVE-2021-37416
30 Aug 2021 — Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, es vulnerable a un ataque de tipo XSS reflejado en la página loadframe. • https://blog.stmcyber.com/vulns/cve-2021-37416 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •