CVE-2021-37424
https://notcve.org/view.php?id=CVE-2021-37424
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. ManageEngine ADSelfService Plus versiones anteriores a 6112, es vulnerable a una toma de control de cuentas de usuario de dominio • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release https://www.manageengine.com •
CVE-2021-37422
https://notcve.org/view.php?id=CVE-2021-37422
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, es vulnerable a una inyección SQL mientras se vinculan las bases de datos • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2021-37423
https://notcve.org/view.php?id=CVE-2021-37423
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, son vulnerables a una toma de posesión de aplicaciones vinculadas • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release •
CVE-2021-37414
https://notcve.org/view.php?id=CVE-2021-37414
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. Zoho ManageEngine DesktopCentral antes de la versión 10.0.709 permite a cualquiera obtener la APIKEY de un usuario válido sin necesidad de autenticación • https://www.manageengine.com/products/desktop-central/help/introduction/release_notes.html https://www.manageengine.com/products/desktop-central/improper-access-control.html • CWE-287: Improper Authentication •
CVE-2021-40539 – Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. Zoho ManageEngine ADSelfService Plus versiones 6113 y anteriores, es vulnerable a una omisión de autenticación de la API REST con una ejecución de código remota resultante Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. • https://github.com/synacktiv/CVE-2021-40539 https://github.com/DarkSprings/CVE-2021-40539 http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authentication-Bypass-Code-Execution.html https://www.manageengine.com https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html https://attackerkb.com/topics/DMSNq5zgcW/cve-2021-40539/rapid7-analysis https://www.synacktiv.com/en/publications/how-to-exploit-cve-2021-40539-on-manageeng • CWE-706: Use of Incorrectly-Resolved Name or Reference •