Impact
Zohocorp ManageEngine ADSelfService Plus versions prior to build 7001 contain a flaw in the REST API that allows an attacker to circumvent authentication controls and obtain unauthorized access. This unauthorized access can lead to a compromise of the service’s administrative or user privileges and potentially expose sensitive information or allow further lateral movement. The weakness is a classic example of CWE‑306, where lack of proper authentication enforcement is the root cause.
Affected Systems
The vulnerability affects Zohocorp ManageEngine ADSelfService Plus for all installations using builds older than 7001. Administrators should verify the exact build number and determine whether the product is on or before the affected version.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating a high severity risk. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that it has not yet been widely exploited in the field but remains a significant concern. The likely attack vector is via the exposed REST API; an attacker who can reach the API endpoint and craft requests may trigger the bypass mechanism and gain unauthenticated or destructive control over the system.
OpenCVE Enrichment