Skip to main content

Vendor/product archive

zohocorp / manageengine_adselfservice_plus CVEs

Beta · best-effort

51 CVEs tagged to zohocorp / manageengine_adselfservice_plus18 Critical, 10 High, 23 Medium, 0 Low, 0 Unrated.

CVE-2025-11250

Published Jan 13, 2026

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-1723

Published Mar 3, 2025

Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have th…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0252

Published Jan 11, 2024

ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35719

Published Sep 6, 2023

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35854

Published Jun 20, 2023

Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby ac…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-34829

Published Jul 4, 2022

Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28987

Published May 20, 2022

Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28810

Published Apr 18, 2022

Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom scrip…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-20148

Published Jan 3, 2022

ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. Whe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20147

Published Jan 3, 2022

ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40539

Published Sep 7, 2021

Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

CVSS 9.8 · Critical
evidence mentions
32
Buzz score
72.5
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 51 CVEsPage 1 of 3