Username Enumeration Vulnerability in Zoho ManageEngine ADSelfService Plus
CVE-2022-28987

5.3MEDIUM

Key Information:

Vendor

Zohocorp

Vendor
CVE Published:
20 May 2022

What is CVE-2022-28987?

A vulnerability in Zoho ManageEngine ADSelfService Plus allows attackers to exploit the login feature via a specially crafted POST request. This security flaw enables unauthorized users to harvest valid usernames from the system. This can lead to further attacks, making it critical for organizations using this software to take immediate action to secure their applications and ensure that all versions are updated to the latest release.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.