manageengine_adselfservice_plus vulnerabilities
CVEs whose affected-version data names the manageengine_adselfservice_plus package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2022-47966Critical· 9.8CISA KEVPoCMultiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in t…
▾ Hadalzohocorp · manageengine_access_manager_plusEPSS 100%via NVD
CVE-2018-5353Critical· 9.8PoCThe custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser w…
▾ Abyssalzohocorp · manageengine_adselfservice_plusEPSS 11%via NVD