ManageEngine ADSelfService Plus Account Takeover Vulnerability

Vulnerability

A session mishandling vulnerability in ManageEngine ADSelfService Plus versions through 6510 allows valid account holders to exploit the issue, leading to unauthorized access to user enrollment data. This vulnerability could result in account takeovers, especially when multi-factor authentication (MFA) is not enabled for ADSelfService Plus login.

Impact

Exploitation of this vulnerability could allow for unauthorized access to user accounts, potentially leading to account takeovers.

Remediation

Users can update to ManageEngine ADSelfService Plus version 6511 or later to address this vulnerability. Instructions for updating are available on the ManageEngine website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
5.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.