PT-2019-18444 · Zoho Manageengine · Adselfservice Plus
Dominique Righetto
·
Published
2019-03-18
·
Updated
2021-07-21
·
CVE-2019-7161
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ADSelfService Plus versions 5.x through build 5704
Description
An issue was discovered where the software uses fixed ciphering keys to protect information. This gives an attacker the capacity to decipher any protected data.
Recommendations
For versions 5.x through build 5704, update to a version later than build 5704 to resolve the issue.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adselfservice Plus