Lucene search

K
nvd[email protected]NVD:CVE-2022-36413
HistoryMar 23, 2023 - 8:15 p.m.

CVE-2022-36413

2023-03-2320:15:14
CWE-307
web.nvd.nist.gov
1
zoho
manageengine
adselfservice
vulnerability
password reset
idm applications

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.3

Confidence

High

EPSS

0.013

Percentile

86.2%

Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.

Affected configurations

Nvd
Node
zohocorpmanageengine_adselfservice_plusRange<6.2
OR
zohocorpmanageengine_adselfservice_plusMatch6.26200
OR
zohocorpmanageengine_adselfservice_plusMatch6.26201
OR
zohocorpmanageengine_adselfservice_plusMatch6.26202
OR
zohocorpmanageengine_adselfservice_plusMatch6.26203
OR
zohocorpmanageengine_adselfservice_plusMatch6.26204
OR
zohocorpmanageengine_adselfservice_plusMatch6.26205
OR
zohocorpmanageengine_adselfservice_plusMatch6.26206
OR
zohocorpmanageengine_adselfservice_plusMatch6.26207
OR
zohocorpmanageengine_adselfservice_plusMatch6.26208
OR
zohocorpmanageengine_adselfservice_plusMatch6.26209
OR
zohocorpmanageengine_adselfservice_plusMatch6.26210
OR
zohocorpmanageengine_adselfservice_plusMatch6.26211
OR
zohocorpmanageengine_adselfservice_plusMatch6.26212
OR
zohocorpmanageengine_adselfservice_plusMatch6.26213
OR
zohocorpmanageengine_adselfservice_plusMatch6.26214
OR
zohocorpmanageengine_adselfservice_plusMatch6.26215
OR
zohocorpmanageengine_adselfservice_plusMatch6.26216
OR
zohocorpmanageengine_adselfservice_plusMatch6.26217
VendorProductVersionCPE
zohocorpmanageengine_adselfservice_plus*cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6200:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6201:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6202:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6203:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6204:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6205:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6206:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6207:*:*:*:*:*:*
zohocorpmanageengine_adselfservice_plus6.2cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:6.2:6208:*:*:*:*:*:*
Rows per page:
1-10 of 191

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.3

Confidence

High

EPSS

0.013

Percentile

86.2%

Related for NVD:CVE-2022-36413