PT-2022-22380 · Zoho · Zoho Manageengine Adselfservice Plus
Skay
·
Published
2022-07-04
·
Updated
2022-07-13
·
CVE-2022-34829
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Zoho ManageEngine ADSelfService Plus versions prior to 6203
Description
The issue allows for a denial of service, resulting in an application restart, via a crafted payload sent to the "Mobile App Deployment API" endpoint.
Recommendations
For versions prior to 6203, update to version 6203 or later to resolve the issue. As a temporary workaround, consider restricting access to the Mobile App Deployment API endpoint until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zoho Manageengine Adselfservice Plus