CVE-2021-37423
https://notcve.org/view.php?id=CVE-2021-37423
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, son vulnerables a una toma de posesión de aplicaciones vinculadas • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release •
CVE-2021-40539 – Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2021-40539
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. Zoho ManageEngine ADSelfService Plus versiones 6113 y anteriores, es vulnerable a una omisión de autenticación de la API REST con una ejecución de código remota resultante Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. • https://github.com/synacktiv/CVE-2021-40539 https://github.com/DarkSprings/CVE-2021-40539 http://packetstormsecurity.com/files/165085/ManageEngine-ADSelfService-Plus-Authentication-Bypass-Code-Execution.html https://www.manageengine.com https://www.manageengine.com/products/self-service-password/kb/how-to-fix-authentication-bypass-vulnerability-in-REST-API.html https://attackerkb.com/topics/DMSNq5zgcW/cve-2021-40539/rapid7-analysis https://www.synacktiv.com/en/publications/how-to-exploit-cve-2021-40539-on-manageeng • CWE-706: Use of Incorrectly-Resolved Name or Reference •
CVE-2021-37421
https://notcve.org/view.php?id=CVE-2021-37421
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, son vulnerables a una evasión de la restricción de acceso al portal de administración. • https://blog.stmcyber.com/vulns/cve-2021-37421 https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6104-released-with-an-important-security-fixes • CWE-345: Insufficient Verification of Data Authenticity •
CVE-2021-37417
https://notcve.org/view.php?id=CVE-2021-37417
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, permiten omitir el CAPTCHA debido a una comprobación inapropiada de los parámetros. • https://blog.stmcyber.com/vulns/cve-2021-37417 • CWE-287: Improper Authentication •
CVE-2021-37416
https://notcve.org/view.php?id=CVE-2021-37416
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, es vulnerable a un ataque de tipo XSS reflejado en la página loadframe. • https://blog.stmcyber.com/vulns/cve-2021-37416 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •