Username Enumeration Vulnerability in Zoho ManageEngine ADSelfService Plus
CVE-2022-28987
5.3MEDIUM
What is CVE-2022-28987?
A vulnerability in Zoho ManageEngine ADSelfService Plus allows attackers to exploit the login feature via a specially crafted POST request. This security flaw enables unauthorized users to harvest valid usernames from the system. This can lead to further attacks, making it critical for organizations using this software to take immediate action to secure their applications and ensure that all versions are updated to the latest release.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved