ManageEngine ADSelfService Plus
cpe:2.3:a:zohocorp:manageengine_adselfservice_plus:*:*:*:*:*:*:*
- <= 6510
A session mishandling vulnerability in ManageEngine ADSelfService Plus versions through 6510 allows valid account holders to exploit the issue, leading to unauthorized access to user enrollment data. This vulnerability could result in account takeovers, especially when multi-factor authentication (MFA) is not enabled for ADSelfService Plus login.
Exploitation of this vulnerability could allow for unauthorized access to user accounts, potentially leading to account takeovers.
Users can update to ManageEngine ADSelfService Plus version 6511 or later to address this vulnerability. Instructions for updating are available on the ManageEngine website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.