ManageEngine ADSelfService Plus < build 6114 REST API Authentication Bypass

critical Nessus Plugin ID 153147

Version 1.13

Dec 1, 2023, 2:20 PM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:H/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:H/RL:O/RC:C")
  • Exploit attributes ("Exploited by malware" set to "True")

Plugin Feed: 202312011420

Version 1.12

May 26, 2023, 10:03 PM

  • CEA reference

Plugin Feed: 202305262203

Version 1.11

Apr 25, 2023, 11:11 PM

  • CVSS temporal metrics (Adjust exploitability metrics for CISA KEV vulnerabilities)

Plugin Feed: 202304252311

Version 1.10

Dec 1, 2022, 5:53 PM

  • CISA reference
  • IAVM reference

Plugin Feed: 202212011753

* Changelogs are generally available for changes made after Nov 1, 2022