PT-2020-15837 · Zoho Manageengine · Adselfservice Plus+10
Florian Hauser
·
Published
2020-08-31
·
Updated
2020-09-10
·
CVE-2020-24786
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine Exchange Reporter Plus versions prior to build number 5510
Zoho ManageEngine AD360 versions prior to build number 4228
Zoho ManageEngine ADSelfService Plus versions prior to build number 5817
Zoho ManageEngine DataSecurity Plus versions prior to build number 6033
Zoho ManageEngine RecoverManager Plus versions prior to build number 6017
Zoho ManageEngine EventLog Analyzer versions prior to build number 12136
Zoho ManageEngine ADAudit Plus versions prior to build number 6052
Zoho ManageEngine O365 Manager Plus versions prior to build number 4334
Zoho ManageEngine Cloud Security Plus versions prior to build number 4110
Zoho ManageEngine ADManager Plus versions prior to build number 7055
Zoho ManageEngine Log360 versions prior to build number 5166
Description
An issue was discovered in the specified Zoho ManageEngine products. The remotely accessible Java servlet
com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. This allows system integration properties to be modified, potentially leading to a full ManageEngine suite compromise.Recommendations
For Zoho ManageEngine Exchange Reporter Plus versions prior to build number 5510, update to build number 5510 or later.
For Zoho ManageEngine AD360 versions prior to build number 4228, update to build number 4228 or later.
For Zoho ManageEngine ADSelfService Plus versions prior to build number 5817, update to build number 5817 or later.
For Zoho ManageEngine DataSecurity Plus versions prior to build number 6033, update to build number 6033 or later.
For Zoho ManageEngine RecoverManager Plus versions prior to build number 6017, update to build number 6017 or later.
For Zoho ManageEngine EventLog Analyzer versions prior to build number 12136, update to build number 12136 or later.
For Zoho ManageEngine ADAudit Plus versions prior to build number 6052, update to build number 6052 or later.
For Zoho ManageEngine O365 Manager Plus versions prior to build number 4334, update to build number 4334 or later.
For Zoho ManageEngine Cloud Security Plus versions prior to build number 4110, update to build number 4110 or later.
For Zoho ManageEngine ADManager Plus versions prior to build number 7055, update to build number 7055 or later.
For Zoho ManageEngine Log360 versions prior to build number 5166, update to build number 5166 or later.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ad360
Adaudit Plus
Admanager Plus
Adselfservice Plus
Cloud Security Plus
Datasecurity Plus
Eventlog Analyzer
Exchange Reporter Plus
Log360
O365 Manager Plus
Recovermanager Plus